CVE-2025-48826
8.8Planet · WGR-500
A format string vulnerability in the formPingCmd function of Planet WGR-500 v1.3411b190912 allows remote attackers to trigger memory corruption via crafted HTTP requests.
Executive summary
A critical format string vulnerability in the Planet WGR-500 router allows authenticated attackers to execute arbitrary code or cause system crashes through memory corruption.
Vulnerability
This is a format string vulnerability (CWE-134) located within the formPingCmd functionality. It requires the attacker to have low-level privileges to send the malicious HTTP requests that trigger the memory corruption.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high severity risk that could lead to full system compromise. If exploited, an attacker could gain unauthorized access, disrupt network services, or execute arbitrary code, leading to significant operational downtime and potential data exposure.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict access to the device management interface to trusted internal networks only. Contact the vendor for the latest firmware updates or security guidance regarding this specific model.
Proactive Monitoring: Monitor device logs for unusual HTTP request patterns or unexpected system reboots that may indicate exploitation attempts.
Compensating Controls: Implement network segmentation to ensure the management interface is not exposed to the public internet or untrusted segments. A Web Application Firewall or similar inspection tool may assist in identifying and blocking malformed HTTP requests targeting the ping command function.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability, this issue poses a significant risk to the integrity and availability of the affected hardware. Administrators must prioritize isolating the device from external exposure and monitor for any vendor-released firmware updates to remediate the underlying flaw as soon as they become available.
Sources
Originally found and disclosed by Discovered by Francesco Benvenuto of Cisco Talos., per the CVE Program record.