CVE-2025-57293: Command Injection
A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multipppoe API, processed by the sub423930 function in /usr/bin/webmgnt. The phyinterface parameter is not sanitized, allowing attackers to inject arbitrary commands via a POST request to /cgi-bin/mbox-config?method=SET§ion=multipppoe. When the action parameter is set to "oneclickredial", the unsanitized phyinterface is used in a system() call, enabling execution of malicious commands. This can lead to unauthorized access to sensitive files, execution of arbitrary code, or full device compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57293?
CVE-2025-57293 is classified as a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2025-57293?
To mitigate CVE-2025-57293, ensure you update the firmware of the COMFAST CF-XR11 router to the latest version provided by the vendor.
What impact does CVE-2025-57293 have on affected systems?
CVE-2025-57293 allows attackers to execute arbitrary commands on vulnerable devices remotely, compromising system integrity.
Which devices are affected by CVE-2025-57293?
CVE-2025-57293 specifically affects COMFAST CF-XR11 devices running firmware version V2.7.2.
What type of vulnerability is CVE-2025-57293?
CVE-2025-57293 is a command injection vulnerability found in the multi_pppoe API of affected devices.