PT-2026-46292 · Neterbit · Nw-431F Router
CVE-2025-67447
·
Published
2026-06-04
·
Updated
2026-06-05
CVSS v3.1
9.8
Critical
| Vector | AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
Neterbit NW-431F Router versions prior to 20241014-IR03
Description
The network diagnosis (ping) module allows OS command injection because the application fails to properly sanitize user input in the IP address field before passing it to the system's ping command. This allows an attacker to inject and execute arbitrary OS commands with the privileges of the web server.
Recommendations
Update to a version newer than 20241014-IR03.
As a temporary workaround, restrict access to the network diagnosis (ping) module to minimize the risk of exploitation.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nw-431F Router