CVE-2025-54399
8.8Planet · WGR-500
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of the Planet WGR-500 router, allowing remote code execution via crafted HTTP requests.
Executive summary
A critical stack-based buffer overflow vulnerability in the Planet WGR-500 router allows authenticated attackers to execute arbitrary code.
Vulnerability
This vulnerability is a stack-based buffer overflow occurring within the formPingCmd function, specifically triggered by the ipaddr parameter. An authenticated attacker can send specially crafted HTTP requests to the vulnerable endpoint to overwrite the stack and potentially achieve arbitrary code execution.
Business impact
The ability for an attacker to execute arbitrary code on network infrastructure poses a severe threat to internal systems. Successful exploitation could lead to full device compromise, unauthorized access to network traffic, and potential pivoting into private internal segments, resulting in significant data loss or service disruption. Given the CVSS score of 8.8, this vulnerability represents a high-risk security flaw that requires immediate attention.
Remediation
Immediate Action: Since no patch is currently identified, isolate the affected WGR-500 devices from the network or restrict access to the web management interface to trusted administrative subnets only.
Proactive Monitoring: Monitor network traffic for unusual HTTP requests targeting the ping functionality, particularly those containing long strings or unexpected characters in the ipaddr parameter.
Compensating Controls: Implement strict access control lists on the management interface and deploy a Web Application Firewall (WAF) rule to drop HTTP requests containing suspicious payloads directed at the vulnerable device.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability is severe due to the potential for remote code execution on core networking hardware. Administrators must treat this as a high-priority risk and restrict access to the administrative interfaces of the affected Planet WGR-500 units immediately until an official firmware update is released by the manufacturer.
More Planet CVEs
Sources
Originally found and disclosed by Discovered by Francesco Benvenuto of Cisco Talos., per the CVE Program record.