PatchSiren

Synway Information Engineering Co., Ltd. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Synway Information Engineering Co., Ltd. CVE published 2026-04-30

CVE-2025-71284

CVE-2025-71284 is a critical OS command injection vulnerability in Synway SMG Gateway Management Software. The vulnerability exists in the RADIUS configuration endpoint at /en/9-2radius.php, allowing unauthenticated remote attackers to inject arbitrary shell commands, potentially leading to remote code execution. This vulnerability was first observed by the Shadowserver Foundation on 2025-07-11 (UTC). Def [truncated]