CVE-2025-54403

8.8

Planet · WGR-500

Multiple OS command injection vulnerabilities in the Planet WGR-500 swctrl functionality allow an authenticated attacker to execute arbitrary commands via the new_password parameter.

Executive summary

A critical OS command injection vulnerability in the Planet WGR-500 router allows authenticated attackers to achieve remote code execution on the device.

Vulnerability

This vulnerability is an OS command injection flaw (CWE-78) located within the swctrl functionality. An authenticated attacker can trigger this by sending a specially crafted network request containing malicious input in the new_password parameter.

Business impact

The ability to execute arbitrary OS commands poses a severe risk to organizational network integrity. Successful exploitation could lead to full device compromise, unauthorized access to sensitive network traffic, or the use of the device as a pivot point for lateral movement within the internal network. With a CVSS score of 8.8, this high-severity flaw requires immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Contact the vendor to obtain the latest firmware update for the WGR-500, as no specific patch version is currently identified.

Proactive Monitoring: Inspect network logs for unusual traffic patterns directed at the swctrl management interface and monitor for unexpected process execution on the device.

Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and employ a firewall to block unauthorized network requests to the vulnerable endpoint.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for complete system takeover, administrators should prioritize securing the management interface of the affected Planet WGR-500 routers. Until a vendor-supplied firmware update is verified and applied, strict network segmentation is essential to limit the attack surface and prevent unauthorized access by potentially malicious actors.

Sources

Originally found and disclosed by Discovered by Francesco Benvenuto of Cisco Talos., per the CVE Program record.