SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sapido
Sapido rb-1732 |
|
| Vendors & Products |
Sapido
Sapido rb-1732 |
Wed, 11 Mar 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges. | |
| Title | SAPIDO RB-1732 V2.0.43 Remote Command Execution via formSysCmd | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-11T18:23:23.999Z
Updated: 2026-03-11T21:40:20.532Z
Reserved: 2026-02-23T17:23:37.579Z
Link: CVE-2019-25487
Updated: 2026-03-11T19:22:28.904Z
Status : Awaiting Analysis
Published: 2026-03-11T19:16:03.157
Modified: 2026-03-12T21:08:22.643
Link: CVE-2019-25487
No data.