CVE-2025-54399: Buffer Overflow
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the ipaddr request parameter for composing the "ping -c <counts> <ipaddr> 2>&1 > %s &" string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54399?
CVE-2025-54399 is categorized as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-54399?
To fix CVE-2025-54399, upgrade to the latest firmware version of the Planet WGR-500 that addresses these buffer overflow vulnerabilities.
What are the risks associated with CVE-2025-54399?
The risks include unauthorized access, remote code execution, and potential denial of service due to exploitability via crafted HTTP requests.
Who is affected by CVE-2025-54399?
Users of the Planet WGR-500 router running version 1.3411b190912 are affected by CVE-2025-54399.
What types of attacks can exploit CVE-2025-54399?
CVE-2025-54399 can be exploited through specially crafted HTTP requests that trigger stack-based buffer overflows.