PT-2025-26684 · Sapido · Sapido Bre71N+11

An-Wei Kung

+4

·

Published

2025-06-24

·

Updated

2025-06-26

·

CVE-2025-6559

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Sapido BR071n version All Sapido BR261c version All Sapido BR270n version All Sapido BR476n version All Sapido BRC70n version All Sapido BRC70x version All Sapido BRC76n version All Sapido BRD70n version All Sapido BRE70n version All Sapido BRE71n version All Sapido BRF61c version All Sapido BRF71n version All
Description: The issue is an OS Command Injection, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This is due to the improper neutralization of special elements used in an OS command.
Recommendations: Replace the device with a supported model, as the affected models are out of support. For all affected models, consider disabling any remote access features until replacement. Restrict access to the device to minimize the risk of exploitation. Avoid using the device for critical operations until it is replaced. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05178
CVE-2025-6559

Affected Products

Sapido Br071N
Sapido Br261C
Sapido Br270N
Sapido Br476N
Sapido Brc70N
Sapido Brc70X
Sapido Brc76N
Sapido Brd70N
Sapido Bre70N
Sapido Bre71N
Sapido Brf61C
Sapido Brf71N