CVE-2025-71284CRITICAL 9.8EPSS p92.1%

CVE-2025-71284CVE-2025-71284

Description

Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. An unauthenticated remote attacker can inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC).

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.73% probability of exploitation · percentile 92.1% · 2026-06-19T12:03:05Z
Published2026-04-30
Last modified2026-05-05

Underlying weaknesses· 1

CWE-78

References

  1. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/synway/synwaysmg-radius-rce.yaml
  2. https://mp.weixin.qq.com/s/PyepoFSuQ63E3RnpQa9nsA
  3. https://mrxn.net/jswz/synway-9-2radius-rce.html
  4. https://www.synway.net/
  5. https://www.vulncheck.com/advisories/synway-smg-gateway-management-software-os-command-injection-via-radius-address

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-780%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
CVE
CVE-2025-34024
CVE
CVE-2025-34029
CVE
SonicWall SMA100 Appliances OS Command Injection Vulnerability
CVE
CVE-2025-50428
CVE
CVE-2026-0204
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.