← Back to browse · API

CVE-2019-25487

Severity
CRITICAL
CVSS
9.3
EPSS
0.07899
Risk score
39.96
CISA KEV
No
PoC
No
Published
2026-03-11
Modified
2026-07-15
First seen
2026-08-07
Aliases
EUVD-2019-19765, GHSA-C925-88RR-2HQ4
Products
Sapido:RB-1732 2.0.43
Sources
euvd EUVD-2019-19765

Description

SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.

References