PatchSiren cyber security CVE debrief
CVE-2025-71284 Synway Information Engineering Co., Ltd. CVE debrief
CVE-2025-71284 is a critical OS command injection vulnerability in Synway SMG Gateway Management Software. The vulnerability exists in the RADIUS configuration endpoint at /en/9-2radius.php, allowing unauthenticated remote attackers to inject arbitrary shell commands, potentially leading to remote code execution. This vulnerability was first observed by the Shadowserver Foundation on 2025-07-11 (UTC). Defenders should assess exposure, prioritize remediation, and monitor for suspicious activity. The CVE record and NVD entry provide details about the vulnerability, but additional information from other sources is limited.
- Vendor
- Synway Information Engineering Co., Ltd.
- Product
- Synway SMG Gateway Management Software
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-30
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-04-30
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for Synway SMG Gateway Management Software instances, particularly those exposed to untrusted networks, should assess exposure and prioritize remediation. This includes reviewing the current configuration, verifying if instances are reachable from untrusted networks, and implementing input validation and sanitization for user-supplied input. Monitoring for suspicious activity and potential exploitation attempts is also crucial.
Why it matters
CVE-2025-71284 is a critical OS command injection vulnerability in Synway SMG Gateway Management Software that allows unauthenticated remote attackers to potentially execute arbitrary code. Defenders should assess exposure, prioritize remediation, and monitor for suspicious activity.
- Potential remote code execution requires immediate attention
- Unauthenticated exploitation increases risk of compromise
- Limited information available on affected versions and remediation
- Verification of instances and monitoring for suspicious activity is crucial
Technical summary
The vulnerability exists in the RADIUS configuration endpoint at /en/9-2radius.php, where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. This allows unauthenticated remote attackers to inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC).
Defensive priority
High
Recommended defensive actions
- Immediately assess exposure of Synway SMG Gateway Management Software instances to this vulnerability
- Verify if instances are reachable from untrusted networks
- Restrict access to the RADIUS configuration endpoint
- Implement input validation and sanitization for user-supplied input
- Monitor for suspicious activity and potential exploitation attempts
Evidence notes
The vulnerability was first observed by the Shadowserver Foundation on 2025-07-11 (UTC). The CVE record and NVD entry provide details about the vulnerability, but additional information from other sources is limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-71284 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-71284
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-71284 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71284
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/synway/synwaysmg-radius-rce.yaml
[email protected] - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://mp.weixin.qq.com/s/PyepoFSuQ63E3RnpQa9nsA
[email protected] - Exploit, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://mrxn.net/jswz/synway-9-2radius-rce.html
[email protected] - Exploit, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://www.synway.net/
[email protected] - Product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/synway-smg-gateway-management-software-os-command-injection-via-radius-address
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.