CVE-2025-14704

7.3

Shiguangwu · sgwbox N3

Shiguangwu sgwbox N3 version 2.0.25 contains a path traversal vulnerability in the /eshell API component, allowing remote attackers to access unauthorized files.

Executive summary

A remote path traversal vulnerability in Shiguangwu sgwbox N3 version 2.0.25 poses a significant risk of unauthorized file access and information disclosure.

Vulnerability

This is a path traversal vulnerability (CWE-22) located in the /eshell API component. The flaw is exploitable by an unauthenticated remote attacker through direct manipulation of the affected endpoint.

Business impact

The ability for an unauthenticated remote attacker to perform path traversal may lead to the unauthorized disclosure of sensitive configuration files, system credentials, or user data stored on the device. With a CVSS score of 7.3, this vulnerability represents a high risk to data confidentiality, potentially facilitating further network compromise or unauthorized administrative control over the affected hardware.

Remediation

Immediate Action: As the vendor has not provided an official patch or responsive communication, administrators should immediately isolate the affected device from public-facing networks or disable the vulnerable /eshell API functionality if business requirements permit.

Proactive Monitoring: Monitor system logs for unusual HTTP requests targeting the /eshell path, particularly those containing directory traversal sequences such as dot-dot-slash patterns.

Compensating Controls: Implement a Web Application Firewall (WAF) or an edge security device to block incoming requests containing directory traversal sequences before they reach the sgwbox N3 appliance.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists and is documented in the technical write-up provided by the vulnerability reporter.

Analyst recommendation

Given the confirmed existence of a public proof-of-concept and the lack of vendor response, organizations utilizing the Shiguangwu sgwbox N3 must prioritize the containment of this device. Restrict network access to the management interface and API endpoints to trusted internal segments only. Until a formal security update is released, the risk of exploitation remains high and should be managed through strict perimeter controls.

Sources

Originally found and disclosed by rgyue (VulDB User), per the CVE Program record.