Impact
The flaw is a command injection vulnerability in the ipsec_conn interface that allows an attacker to execute arbitrary shell commands with root privileges (CWE‑77). This grants full control over the device, enabling configuration changes, data exfiltration, or the device to be used as a foothold for further attacks.
Affected Systems
The vulnerability affects routers model TR1200 (2.4.15), TR3000 (2.4.21), WR300 (2.4.25), WR1200 (2.4.23), WR1300 (2.4.22), WR1500 (2.3.10), WR3000 (2.4.19), WR3600 (2.3.16), and WR6500 (2.3.15). These devices are inferred to be produced by Cudy, based on the reference URL and firmware branding, though the vendor is not explicitly provided by the CNA.
Risk and Exploitability
The EPSS score of 3 % indicates a low but non‑zero likelihood of exploitation. The CVSS score of 9.8 signifies critical severity, and the vulnerability is not listed in CISA KEV. Attackers can exploit it remotely by sending crafted inputs to the ipsec_conn interface, with no additional prerequisites explicitly stated.
OpenCVE Enrichment