Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended.
History

Tue, 24 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Jun 2025 02:30:00 +0000

Type Values Removed Values Added
Description Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended.
Title Sapido Wireless Router - OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2025-06-24T01:47:25.776Z

Updated: 2025-06-24T15:32:51.258Z

Reserved: 2025-06-24T01:24:44.230Z

Link: CVE-2025-6559

cve-icon Vulnrichment

Updated: 2025-06-24T15:32:26.566Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-24T03:15:35.700

Modified: 2025-06-26T18:58:14.280

Link: CVE-2025-6559

cve-icon Redhat

No data.