CVE-2025-43953

8.8

2wcom · IP-4c

The 2wcom IP-4c web interface allows authenticated administrators or managers to achieve root-level remote code execution via command injection in the ping or traceroute fields.

Executive summary

A critical command injection vulnerability in the 2wcom IP-4c web interface allows authenticated users to execute arbitrary code with root privileges.

Vulnerability

This vulnerability is a command injection flaw located within the ping and traceroute fields of the TCP/IP configuration screen, which permits authenticated admin or manager users to execute system commands as root.

Business impact

Successful exploitation grants an attacker full administrative control over the affected device with root privileges. Given the CVSS score of 8.8, this poses a high risk of total system compromise, unauthorized data access, and potential disruption of broadcast or transmission services managed by the unit.

Remediation

Immediate Action: As no specific patch version is currently identified, administrators should restrict access to the web interface to trusted management networks and monitor the device for unauthorized configuration changes.

Proactive Monitoring: Security teams should audit access logs for unusual activity on the TCP/IP configuration screen and monitor system logs for spawned processes originating from network diagnostic tools.

Compensating Controls: Deploy a Web Application Firewall or network access control list to restrict access to the device management interface to known, authorized IP addresses only.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the linked research repository.

Analyst recommendation

The presence of a public proof-of-concept combined with the ability to achieve root-level execution makes this a high-priority concern. Organizations using 2wcom IP-4c version 2.16 must immediately isolate these devices from untrusted networks and contact the vendor for official remediation guidance.

Sources