Nexxt Solutions · Nexxt Solutions Ncm-X1800 Mesh Router · CVE-2025-52379
**Name of the Vulnerable Software and Affected Versions**
Nexxt Solutions NCM-X1800 Mesh Router firmware versions prior to UV1.2.7
**Description**
Nexxt Solutions NCM-X1800 Mesh Router firmware contains an authenticated command injection issue in the firmware update feature. The `/web/um fileName set.cgi` and `/web/um web upgrade.cgi` API endpoints do not properly sanitize the `upgradeFileName` parameter. This allows authenticated attackers to execute arbitrary OS commands on the device, potentially leading to remote code execution.
**Recommendations**
Update Nexxt Solutions NCM-X1800 Mesh Router firmware to version UV1.2.7 or later.