nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25487 CVE-2019-25487
CRITICAL
SAPIDO RB-1732 V2.0.43 Remote Command Execution via formSysCmd
Record summary
CVE-2019-25487 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
RB-1732Browse Sapido / RB-1732Default status: unaffected | CVE List | 2.0.43 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSAPIDO RB-1732 - Remote Command ExecutionExploitDB exploitby k1nm3n.aotoiNot analyzed1 file
References
4ExploitDB-47031exploit
https://www.exploit-db.com/exploits/47031 VulnCheck Advisory: SAPIDO RB-1732 V2.0.43 Remote Command Execution via formSysCmdThird-party advisory
https://www.vulncheck.com/advisories/sapido-rb-1732-remote-command-execution-via-formsyscmd vulncheck.com
https://www.vulncheck.com/advisories/sapido-rb-remote-command-execution-via-formsyscmd