← back
CVE-2025-58116highCWE-78

CVE-2025-58116

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 1.1%
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in WN-7D36QR and WN-7D36QR/UE devices allows a logged-in user to run any command on the system by injecting malicious OS commands. This could let an attacker take full control of the device.

Technical detail

OS command injection vulnerability in WN-7D36QR/WN-7D36QR/UE due to improper sanitization of user-supplied input in OS command construction. Requires prior authentication; attacker can execute arbitrary system commands with device privileges, potentially leading to complete system compromise.

Summary generated and translated by AI from the official description.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and WN-7D36QR/UE. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote authenticated attacker.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N