Remote Code Execution Vulnerability in WODESYS WD-R608U Router
CVE-2025-65008
9.4CRITICAL
What is CVE-2025-65008?
A security flaw in the WODESYS WD-R608U router, which includes models WDR122B V2.0 and WDR28, permits unauthorized users to execute arbitrary system shell commands via an unprotected langGet parameter in the adm.cgi endpoint. While the vendor received notification about this issue, no details on the vulnerability or its affected versions were provided, leaving users at risk. Only the version WDR28081123OV1.01 has been confirmed as vulnerable, prompting the need for immediate investigation and remediation for other versions.
Affected Version(s)
WD-R608U WDR28081123OV1.01
WDR122B V2.0 WDR28081123OV1.01
WDR28 WDR28081123OV1.01
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Wojciech Cybowski
