PT-2025-52247 · Wodesys · Wdr122B V2.0+2

Wojciech Cybowski

·

Published

2025-12-18

·

Updated

2025-12-18

·

CVE-2025-65008

CVSS v4.0

9.4

Critical

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WODESYS WD-R608U router versions prior to WDR28081123OV1.01 WODESYS WDR122B V2.0 (affected versions not specified) WODESYS WDR28 (affected versions not specified)
Description A lack of input validation in the langGet parameter of the /adm.cgi API endpoint allows for the execution of system shell commands. The vendor was notified but did not provide details regarding vulnerable version ranges. Testing confirmed that version WDR28081123OV1.01 is vulnerable, and other versions may also be affected.
Recommendations Update to version WDR28081123OV1.01 or later. Restrict access to the /adm.cgi endpoint. Sanitize the langGet parameter to prevent command injection.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65008

Affected Products

Wd-R608U Router
Wdr122B V2.0
Wdr28