PT-2025-29880 · Unknown · Netcore Routers+1

H00Die

+1

·

Published

2025-07-16

·

Updated

2025-07-17

·

CVE-2025-34117

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netcore and Netis routers (affected versions not specified)
Description A remote code execution issue exists due to an undocumented backdoor listener on UDP port 53413. An unauthenticated remote attacker can send specially crafted UDP packets to execute arbitrary commands on the affected device. The backdoor uses a hardcoded authentication mechanism and accepts shell commands post-authentication. Some device models include a non-standard implementation of the echo command, which may affect exploitability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Missing Authentication

Hidden Functionality

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-34117

Affected Products

Netcore Routers
Netis Routers