cvedb.io
CVE-2025-71284
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2026-04-30T17:16:25.630 · Last modified 2026-06-17T10:04:00.417

Summary

Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. An unauthenticated remote attacker can inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC).

Affected products

synway — smg_gateway_management_software

Does this affect you?

Add your gear to cvedb and we'll alert you only when synway ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.