Vulnerability Description
SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/47031
- https://www.vulncheck.com/advisories/sapido-rb-1732-remote-command-execution-via
FAQ
What is CVE-2019-25487?
CVE-2019-25487 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endp...
How severe is CVE-2019-25487?
CVE-2019-25487 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-25487?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.