An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling in the undocumented /cgi-bin/rdfs.cgi endpoint. The Client parameter is not sanitized before being passed to a system call, allowing an unauthenticated remote attacker to execute arbitrary commands as the web server user.
CVSS
No CVSS.
References
Configurations
No configuration.
History
15 Jul 2025, 20:07
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-15 13:15
Updated : 2025-07-15 20:07
NVD link : CVE-2025-34103
Mitre link : CVE-2025-34103
CVE.ORG link : CVE-2025-34103
JSON object : View
Products Affected
No product.