CVE-2025-54403: OS Command Injection
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is related to the newpassword request parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54403?
CVE-2025-54403 is considered critical due to the potential for arbitrary command execution via OS command injection.
How do I fix CVE-2025-54403?
To fix CVE-2025-54403, update the firmware of the Planet WGR-500 to the latest version provided by the vendor.
What are the potential impacts of CVE-2025-54403?
The potential impacts of CVE-2025-54403 include unauthorized access and complete control over the affected device.
Who is affected by CVE-2025-54403?
Users of the Planet WGR-500 router with firmware version v1.3411b190912 are affected by CVE-2025-54403.
Is CVE-2025-54403 related to other vulnerabilities?
CVE-2025-54403 may be related to other OS command injection vulnerabilities in similar networking devices.