PT-2025-52247 · Wodesys · Wdr122B V2.0+2
Wojciech Cybowski
·
Published
2025-12-18
·
Updated
2025-12-18
·
CVE-2025-65008
CVSS v4.0
9.4
Critical
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
WODESYS WD-R608U router versions prior to WDR28081123OV1.01
WODESYS WDR122B V2.0 (affected versions not specified)
WODESYS WDR28 (affected versions not specified)
Description
A lack of input validation in the
langGet parameter of the /adm.cgi API endpoint allows for the execution of system shell commands. The vendor was notified but did not provide details regarding vulnerable version ranges. Testing confirmed that version WDR28081123OV1.01 is vulnerable, and other versions may also be affected.Recommendations
Update to version WDR28081123OV1.01 or later.
Restrict access to the
/adm.cgi endpoint.
Sanitize the langGet parameter to prevent command injection.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wd-R608U Router
Wdr122B V2.0
Wdr28