CVE-2025-11073: Keyfactor RG-EW5100BE HTTP POST Request cmd command injection
A vulnerability was detected in Keyfactor RG-EW5100BE EW3.0B11P280EW5100BE-PRO12183019. The affected element is an unknown function of the file /cgi-bin/luci/api/cmd of the component HTTP POST Request Handler. The manipulation of the argument url results in command injection. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11073?
CVE-2025-11073 is classified as a high severity vulnerability due to its potential for command injection.
How do I fix CVE-2025-11073?
To mitigate CVE-2025-11073, update the Keyfactor RG-EW5100BE device to the latest firmware version provided by the vendor.
What type of vulnerability is CVE-2025-11073?
CVE-2025-11073 is a command injection vulnerability affecting the HTTP POST Request Handler component.
Which devices are affected by CVE-2025-11073?
CVE-2025-11073 specifically affects the Keyfactor RG-EW5100BE model.
What can attackers achieve by exploiting CVE-2025-11073?
Exploiting CVE-2025-11073 allows attackers to execute arbitrary commands on the affected device.