A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulatio...
Description
A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulation of the argument params causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analyst Comment
Remediation
Update A vulnerability was determined in Shiguangwu sgwbox Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Executive Summary:
A critical remote command injection vulnerability, identified as CVE-2025-14705, has been discovered in multiple Shiguangwu sgwbox products. This flaw allows a remote, unauthenticated attacker to execute arbitrary commands on an affected device by sending a malicious request to the SHARESERVER feature. Successful exploitation could lead to a complete system compromise, posing a severe risk to data confidentiality, integrity, and availability.
Vulnerability Details
CVE-ID: CVE-2025-14705
Affected Software: Shiguangwu sgwbox Multiple Products
Affected Versions: sgwbox N3 version 2.0.25 is confirmed to be vulnerable. Other products and versions may also be affected; see vendor advisory for a complete list.
Vulnerability: The vulnerability is a command injection flaw within an unspecified function of the SHARESERVER component. An attacker can craft a malicious request manipulating the
paramsargument to include operating system commands. When the application processes this input without proper sanitization, it executes the injected commands with the privileges of the application, which could lead to a full system takeover. The attack is low-complexity and can be initiated remotely without requiring any user authentication.Business Impact
This vulnerability carries a critical severity rating with a CVSS score of 9.8. Exploitation by a remote attacker could result in the complete compromise of the affected device. Potential consequences include theft of sensitive data, deployment of ransomware or other malware, disruption of critical services, and using the compromised device as a pivot point to launch further attacks against the internal network. The public availability of an exploit significantly increases the likelihood of attack, posing an immediate and severe risk to the organization.
Remediation Plan
Immediate Action: Update affected Shiguangwu sgwbox products to the latest patched version immediately. If a patch is not yet available, consider the compensating controls listed below as a temporary measure.
Proactive Monitoring: Actively monitor network traffic and device logs for signs of exploitation. Look for unusual requests to the SHARESERVER feature, especially those containing shell metacharacters (e.g.,
;,|,&&,$(),`) within theparamsargument. Review access logs for connections from untrusted IP addresses attempting to interact with this component.Compensating Controls: If patching is not immediately possible, implement the following controls:
Exploitation Status
Public Exploit Available: true
Analyst Notes: As of Dec 15, 2025, a proof-of-concept exploit for this vulnerability has been publicly disclosed. The vendor has been unresponsive to the disclosure, which may delay the availability of an official patch. This combination of a public exploit and an unresponsive vendor significantly elevates the risk profile of this vulnerability.
Analyst Recommendation
Given the critical CVSS score of 9.8, the remote and unauthenticated nature of the attack, and the public availability of an exploit, this vulnerability requires immediate attention. Organizations must prioritize patching affected Shiguangwu sgwbox devices without delay. Although this CVE is not currently on the CISA KEV list, its characteristics make it a likely candidate for widespread exploitation. If a patch is unavailable due to vendor non-responsiveness, the compensating controls outlined above must be implemented as an urgent priority to mitigate the high risk of compromise.