Record summary

CVE-2019-25487 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

SAPIDO RB-1732 V2.0.43 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the formSysCmd endpoint. Attackers can send POST requests with the sysCmd parameter containing shell commands to execute code on the device with router privileges.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List2.0.43affected

Proofs of concept

1

Catalogued exploits

ExploitDBSAPIDO RB-1732 - Remote Command ExecutionExploitDB exploitby k1nm3n.aotoiNot analyzed1 file
ExploitDB

PoC details

References

4