Remote Code Execution Vulnerability in WODESYS WD-R608U Router
CVE-2025-65008

9.4CRITICAL

Key Information:

Vendor

Wodesys

Vendor
CVE Published:
18 December 2025

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2025-65008?

A security flaw in the WODESYS WD-R608U router, which includes models WDR122B V2.0 and WDR28, permits unauthorized users to execute arbitrary system shell commands via an unprotected langGet parameter in the adm.cgi endpoint. While the vendor received notification about this issue, no details on the vulnerability or its affected versions were provided, leaving users at risk. Only the version WDR28081123OV1.01 has been confirmed as vulnerable, prompting the need for immediate investigation and remediation for other versions.

Affected Version(s)

WD-R608U WDR28081123OV1.01

WDR122B V2.0 WDR28081123OV1.01

WDR28 WDR28081123OV1.01

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wojciech Cybowski
.
CVE-2025-65008 : Remote Code Execution Vulnerability in WODESYS WD-R608U Router