OS Command Injection Vulnerability in Planet WGR-500
CVE-2025-54404
8.8HIGH
What is CVE-2025-54404?
Multiple OS command injection vulnerabilities have been identified in the swctrl functionality of Planet WGR-500 v1.3411b190912. By crafting specific network requests, an attacker can exploit these vulnerabilities to execute arbitrary commands on the device. This issue is primarily linked to the new_device_name
request parameter, which, when manipulated, allows unauthorized command execution, posing a significant threat to network security.
Affected Version(s)
WGR-500 v1.3411b190912