PT-2025-51208 · Shiguangwu · Sgwbox N3
Rgyue
·
Published
2025-12-15
·
Updated
2025-12-15
·
CVE-2025-14709
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Shiguangwu sgwbox N3 version 2.0.25
Description
A buffer overflow issue exists in the file
/usr/sbin/http eshell server component WIRELESSCFGGET Interface of Shiguangwu sgwbox N3. The manipulation of the params argument can lead to a buffer overflow, potentially allowing for remote exploitation. The exploit for this issue has been publicly disclosed.Recommendations
Disable the WIRELESSCFGGET Interface as a temporary workaround until a patch is available.
Restrict access to the file
/usr/sbin/http eshell server to minimize the risk of exploitation.
Avoid using the params argument in the WIRELESSCFGGET Interface until the issue is resolved.Exploit
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sgwbox N3