LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2019-25487

Published
CVSS9.8
Severitycritical
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.

References

← Back to the CVE Tracker

Our coverage of CVE-2019-25487

No stories yet. This page updates automatically when we publish reporting that references CVE-2019-25487.