PT-2025-26684 · Sapido · Sapido Bre71N+11
An-Wei Kung
+4
·
Published
2025-06-24
·
Updated
2025-06-26
·
CVE-2025-6559
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Sapido BR071n version All
Sapido BR261c version All
Sapido BR270n version All
Sapido BR476n version All
Sapido BRC70n version All
Sapido BRC70x version All
Sapido BRC76n version All
Sapido BRD70n version All
Sapido BRE70n version All
Sapido BRE71n version All
Sapido BRF61c version All
Sapido BRF71n version All
Description:
The issue is an OS Command Injection, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This is due to the improper neutralization of special elements used in an OS command.
Recommendations:
Replace the device with a supported model, as the affected models are out of support.
For all affected models, consider disabling any remote access features until replacement.
Restrict access to the device to minimize the risk of exploitation.
Avoid using the device for critical operations until it is replaced.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sapido Br071N
Sapido Br261C
Sapido Br270N
Sapido Br476N
Sapido Brc70N
Sapido Brc70X
Sapido Brc76N
Sapido Brd70N
Sapido Bre70N
Sapido Bre71N
Sapido Brf61C
Sapido Brf71N