CVE-2025-54404: OS Command Injection
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is related to the newdevicename request parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54404?
CVE-2025-54404 has a high severity due to potential arbitrary command execution through OS command injection.
How do I fix CVE-2025-54404?
Fix CVE-2025-54404 by applying the latest firmware update from Planet for the WGR-500 device.
What are the risks associated with CVE-2025-54404?
The risks include unauthorized access and control over the device, leading to data breaches or network compromise.
What versions of the Planet WGR-500 are affected by CVE-2025-54404?
Planet WGR-500 version 1.3411b190912 is affected by CVE-2025-54404.
How does CVE-2025-54404 exploit the system?
CVE-2025-54404 exploits the system by allowing an attacker to send specially crafted network requests that trigger OS command injection.