PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-71284 Synway Information Engineering Co., Ltd. CVE debrief

CVE-2025-71284 is a critical OS command injection vulnerability in Synway SMG Gateway Management Software. The vulnerability exists in the RADIUS configuration endpoint at /en/9-2radius.php, allowing unauthenticated remote attackers to inject arbitrary shell commands, potentially leading to remote code execution. This vulnerability was first observed by the Shadowserver Foundation on 2025-07-11 (UTC). Defenders should assess exposure, prioritize remediation, and monitor for suspicious activity. The CVE record and NVD entry provide details about the vulnerability, but additional information from other sources is limited.

Vendor
Synway Information Engineering Co., Ltd.
Product
Synway SMG Gateway Management Software
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-30
Original CVE updated
2026-09-30
Advisory published
2026-04-30
Advisory updated
2026-09-30

Who should care

Defenders responsible for Synway SMG Gateway Management Software instances, particularly those exposed to untrusted networks, should assess exposure and prioritize remediation. This includes reviewing the current configuration, verifying if instances are reachable from untrusted networks, and implementing input validation and sanitization for user-supplied input. Monitoring for suspicious activity and potential exploitation attempts is also crucial.

Why it matters

CVE-2025-71284 is a critical OS command injection vulnerability in Synway SMG Gateway Management Software that allows unauthenticated remote attackers to potentially execute arbitrary code. Defenders should assess exposure, prioritize remediation, and monitor for suspicious activity.

  • Potential remote code execution requires immediate attention
  • Unauthenticated exploitation increases risk of compromise
  • Limited information available on affected versions and remediation
  • Verification of instances and monitoring for suspicious activity is crucial

Technical summary

The vulnerability exists in the RADIUS configuration endpoint at /en/9-2radius.php, where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. This allows unauthenticated remote attackers to inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC).

Defensive priority

High

Recommended defensive actions

  • Immediately assess exposure of Synway SMG Gateway Management Software instances to this vulnerability
  • Verify if instances are reachable from untrusted networks
  • Restrict access to the RADIUS configuration endpoint
  • Implement input validation and sanitization for user-supplied input
  • Monitor for suspicious activity and potential exploitation attempts

Evidence notes

The vulnerability was first observed by the Shadowserver Foundation on 2025-07-11 (UTC). The CVE record and NVD entry provide details about the vulnerability, but additional information from other sources is limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-71284 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-71284

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-71284 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71284

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.