PT-2025-29563 · Nexxt Solutions · Ncm-X1800 Mesh Router

Vagebondcur

·

Published

2025-07-15

·

Updated

2025-07-15

·

CVE-2025-52377

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nexxt Solutions NCM-X1800 Mesh Router versions UV1.2.7 and below
Description A command injection issue exists in the web management interface's ping and traceroute functionality of the Nexxt Solutions NCM-X1800 Mesh Router. The application does not properly sanitize user input in the Ping host text parameter before passing it to the underlying system command. This allows authenticated attackers to inject and execute arbitrary shell commands as the root user via the /web/um ping set.cgi endpoint.
Recommendations Versions prior to UV1.2.7 are affected. Update to version UV1.2.7 or later to resolve this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-52377

Affected Products

Ncm-X1800 Mesh Router