PT-2026-24781 · Sapido · Rb-1732
K1Nm3N.Aotoi
·
Published
2026-03-11
·
Updated
2026-03-11
·
CVE-2019-25487
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAPIDO RB-1732 version 2.0.43
Description
The device contains a remote command execution issue that allows attackers to execute arbitrary system commands without authentication. Attackers can send malicious input to the
formSysCmd API endpoint. Specifically, attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.Recommendations
Apply input validation to the
sysCmd parameter of the formSysCmd API endpoint.
Restrict access to the formSysCmd endpoint.
Disable the formSysCmd endpoint if it is not essential for device operation.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rb-1732