CRITICAL
Synway Information Engineering Co., Ltd.
CVE published 2026-04-30
CVE-2025-71284
CVE-2025-71284 is a critical OS command injection vulnerability in Synway SMG Gateway Management Software. The vulnerability exists in the RADIUS configuration endpoint at /en/9-2radius.php, allowing unauthenticated remote attackers to inject arbitrary shell commands, potentially leading to remote code execution. This vulnerability was first observed by the Shadowserver Foundation on 2025-07-11 (UTC). Def [truncated]