CVE-2025-52379

MEDIUM

Nexxt Solutions NCM-X1800 Mesh Router <UV1.2.7 - Command Injection

Title source: llm
STIX 2.1

Description

Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 and below contains an authenticated command injection vulnerability in the firmware update feature. The /web/um_fileName_set.cgi and /web/um_web_upgrade.cgi endpoints fail to properly sanitize the upgradeFileName parameter, allowing authenticated attackers to execute arbitrary OS commands on the device, resulting in remote code execution.

Scores

CVSS v3 5.4
EPSS 0.0024
EPSS Percentile 46.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Published Jul 15, 2025
Tracked Since Feb 18, 2026