CVE-2025-54402
8.8Planet · WGR-500
Multiple stack-based buffer overflow vulnerabilities in the formPingCmd function of Planet WGR-500 allow remote code execution via crafted HTTP requests.
Executive summary
A critical stack-based buffer overflow vulnerability in the Planet WGR-500 router allows authenticated attackers to execute arbitrary code.
Vulnerability
The vulnerability exists within the formPingCmd functionality, specifically triggered by malicious input provided to the submit-url and ipaddr request parameters. This flaw requires an authenticated user to successfully trigger the overflow and achieve potential remote code execution.
Business impact
The exploitation of this vulnerability can result in full system compromise, allowing an attacker to execute arbitrary commands with the privileges of the web service. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to unauthorized network access, data interception, or the permanent disruption of network services provided by the affected device.
Remediation
Immediate Action: Contact the vendor for firmware update availability and apply it immediately to the affected Planet WGR-500 units.
Proactive Monitoring: Review device access logs for unusual HTTP requests directed at the ping utility or administrative endpoints.
Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the severity of this stack-based buffer overflow, immediate action is required to secure vulnerable infrastructure. Security teams should prioritize patching this device once a vendor update is released and ensure that administrative access is strictly limited to authorized personnel to prevent the necessary authentication prerequisite from being met by unauthorized actors.
Sources
Originally found and disclosed by Discovered by Francesco Benvenuto of Cisco Talos., per the CVE Program record.