CVE-2025-54401
8.8Planet · WGR-500
Multiple stack-based buffer overflow vulnerabilities in the formPingCmd function of the Planet WGR-500 allow remote code execution via crafted HTTP requests to the submit-url parameter.
Executive summary
A stack-based buffer overflow vulnerability in the Planet WGR-500 router allows authenticated attackers to execute arbitrary code, posing a significant risk to network integrity.
Vulnerability
This is a stack-based buffer overflow (CWE-121) occurring within the formPingCmd functionality. An attacker with low privileges can trigger the vulnerability by sending a specially crafted series of HTTP requests targeting the submit-url parameter.
Business impact
Successful exploitation allows an attacker to achieve full control over the affected network device, potentially leading to unauthorized access to internal network traffic, credential theft, or the use of the device as a pivot point for lateral movement. Given the CVSS score of 8.8, this vulnerability represents a high-severity risk that could compromise the confidentiality, integrity, and availability of the entire local network segment.
Remediation
Immediate Action: Contact the vendor immediately to obtain firmware updates, as no public patch is currently confirmed for this specific version.
Proactive Monitoring: Monitor network traffic for anomalous HTTP requests directed at the administrative interface and review device logs for unexpected process restarts or crashes.
Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and implement a Web Application Firewall or similar filtering mechanism to block suspicious malformed HTTP requests.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent unauthorized code execution on the gateway device. Administrators should prioritize isolating the affected WGR-500 units from external network exposure until a vendor-supplied firmware update is verified and applied.
More Planet CVEs
Sources
Originally found and disclosed by Discovered by Francesco Benvenuto of Cisco Talos., per the CVE Program record.