Record summary

CVE-2019-25483 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.

Description

Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k contains a restricted shell escape vulnerability that allows local users to bypass command restrictions by using the command substitution operator $( ). Attackers can inject arbitrary commands through the $( ) syntax when passed as arguments to allowed commands like ping to execute unrestricted shell access.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListGE31-412SSG-C01_R10.A2pG039u.d24kaffected

Proofs of concept

1

Catalogued exploits

ExploitDBComtrend-AR-5310 - Restricted Shell EscapeExploitDB exploitby AMRI AmineNot analyzed1 file
ExploitDB

PoC details

References

4