TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply crafted values to execute arbitrary operating system commands as root, resulting in full device compromise.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 19 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Tg8
Tg8 tg8 Firewall
CPEs cpe:2.3:a:tg8:tg8_firewall:-:*:*:*:*:*:*:*
Vendors & Products Tg8
Tg8 tg8 Firewall

Sat, 15 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Togrow
Togrow tg8 Firewall
Vendors & Products Togrow
Togrow tg8 Firewall

Fri, 14 Nov 2025 23:00:00 +0000

Type Values Removed Values Added
Description TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply crafted values to execute arbitrary operating system commands as root, resulting in full device compromise.
Title TG8 Firewall Unauthenticated RCE via runphpcmd.php
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-18T16:20:30.649Z

Reserved: 2025-11-14T20:52:09.108Z

Link: CVE-2021-4470

cve-icon Vulnrichment

Updated: 2025-11-18T16:20:21.654Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-14T23:15:43.087

Modified: 2025-11-18T17:15:57.330

Link: CVE-2021-4470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-15T22:07:38Z

Weaknesses