CVE-2025-22906: Command Injection
Published Jan 16, 2025
·Updated
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.
Affected Software
3 affected components
Re11S Re11S
All of the following
Edimax Re11s Firmware=1.11
Edimax Re11s
Event History
Jan 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22906?
CVE-2025-22906 is considered a critical command injection vulnerability.
2
How do I fix CVE-2025-22906?
To fix CVE-2025-22906, update RE11S to the latest version or apply any provided patches.
3
What type of vulnerability is CVE-2025-22906?
CVE-2025-22906 is defined as a command injection vulnerability.
4
What is the impact of exploiting CVE-2025-22906?
Exploiting CVE-2025-22906 can lead to unauthorized command execution on the affected system.
5
Which software is affected by CVE-2025-22906?
CVE-2025-22906 affects RE11S version 1.11.