PT-2025-48267 · Sdmc · Sdmc Ne6037 Routers

Grzegorz Bronka

·

Published

2025-11-27

·

Updated

2026-01-28

·

CVE-2025-8890

CVSS v4.0

9.3

Critical

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SDMC NE6037 routers versions prior to 7.1.12.2.44
Description The firmware in SDMC NE6037 routers contains a network diagnostics tool susceptible to shell command injection attacks. Exploitation requires an attacker to log in to the router's administrative portal, which is typically accessible only through LAN ports. Successful exploitation could lead to remote code execution.
Recommendations Versions prior to 7.1.12.2.44 should be updated to version 7.1.12.2.44 or later.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8890

Affected Products

Sdmc Ne6037 Routers