CVE-2019-25487: SAPIDO RB-1732 V2.0.43 Remote Command Execution via formSysCmd
SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25487?
CVE-2019-25487 is classified as a critical vulnerability due to its ability to allow unauthenticated remote command execution.
How do I fix CVE-2019-25487?
To fix CVE-2019-25487, update the SAPIDO RB-1732 device firmware to the latest version that addresses this vulnerability.
Who is affected by CVE-2019-25487?
CVE-2019-25487 affects users of the SAPIDO RB-1732 V2.0.43 router due to its remote command execution flaw.
What is the impact of CVE-2019-25487?
The impact of CVE-2019-25487 is that it allows attackers to execute arbitrary system commands, potentially leading to a full system compromise.
Is CVE-2019-25487 exploit publicly available?
Yes, exploits for CVE-2019-25487 are publicly available, which increases the urgency for affected users to address the vulnerability.