CVE-2025-54405: OS Command Injection
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the ipaddr request parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54405?
CVE-2025-54405 is classified as a high severity vulnerability due to the potential for arbitrary command execution.
How do I fix CVE-2025-54405?
To mitigate CVE-2025-54405, it is recommended to update the Planet WGR-500 device to the latest firmware version provided by the manufacturer.
What does CVE-2025-54405 affect?
CVE-2025-54405 affects the Planet WGR-500 router specifically in its formPingCmd functionality.
What kind of attack can exploit CVE-2025-54405?
CVE-2025-54405 can be exploited through specially crafted HTTP requests that lead to OS command injection.
Can CVE-2025-54405 lead to data breaches?
Yes, successful exploitation of CVE-2025-54405 could lead to unauthorized access to the device and potential data breaches.