Remote Code Execution Vulnerability in Netcore and Netis Routers
CVE-2025-34117
Key Information:
- Vendor
Netcore Technology
- Status
- Vendor
- CVE Published:
- 16 July 2025
Badges
What is CVE-2025-34117?
A remote code execution vulnerability affects various models of Netcore and Netis routers with firmware released before August 2014. This issue arises from an undocumented backdoor listener operating on UDP port 53413, allowing unauthenticated remote attackers to send specially crafted UDP packets that can execute arbitrary commands on the impacted devices. The backdoor uses hardcoded authentication, allowing post-authentication shell commands to be executed. Certain models exhibit a unique implementation of the 'echo' command, which may influence how the vulnerability can be exploited.
Affected Version(s)
Router firmware Prior to August 2014
Router firmware Prior to August 2014
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved