peter bassill · operator
$ cve CVE-2025-71284 JSON

CVE-2025-71284

9.8
CRITICAL · CVSS 3.1 · EPSS 5.7% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. An unauthenticated remote attacker can inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.73% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-04-30
Last modified2026-10-07

Affected (1)

VendorProduct
synwaysmg gateway management software

References

→ the Explorer  ·  watch your stack  ·  NVD