{"advisories":[{"id":"EUVD-2025-19210","source":"euvd","title":"A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19210"}],"cve":"CVE-2025-34044","epss":{"score":0.03831},"mitre":{"cpes":[],"created":"2025-06-26T15:51:30.957000+00:00","description":"A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-25 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":9.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"mitre_repo_path":"cves/2025/34xxx/CVE-2025-34044.json","references":["http://www.szwifisky.com/","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/wifisky7-rce.yaml","https://s4e.io/tools/wifisky-7-layer-flow-control-router-remote-code-execution","https://vulncheck.com/advisories/wifisky-flow-control-router-rce","https://www.cnvd.org.cn/flaw/show/CNVD-2021-45363","https://www.variotdbs.pl/vuln/VAR-202107-1715/"],"title":"WIFISKY 7-Layer Flow Control Router Remote Command Execution","updated":"2025-11-17T21:15:30.068000+00:00","vendors":[],"weaknesses":["CWE-78"]},"nvd":{"cpes":[],"created":"2025-06-26T16:15:27.670000+00:00","description":"A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-25 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{"score":9.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}},"nvd_repo_path":"2025/CVE-2025-34044.json","references":["http://www.szwifisky.com/","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/wifisky7-rce.yaml","https://s4e.io/tools/wifisky-7-layer-flow-control-router-remote-code-execution","https://vulncheck.com/advisories/wifisky-flow-control-router-rce","https://www.cnvd.org.cn/flaw/show/CNVD-2021-45363","https://www.variotdbs.pl/vuln/VAR-202107-1715/"],"title":null,"updated":"2026-06-17T09:13:22.153000+00:00","vendors":[],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-06-26T16:00:00+00:00","data":[{"details":{"new":"A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands.","old":null},"type":"description"},{"details":{"new":"WIFISKY 7-Layer Flow Control Router Remote Command Execution","old":null},"type":"title"},{"details":{"added":["CWE-20","CWE-78"],"removed":[]},"type":"weaknesses"},{"details":{"added":["http://www.szwifisky.com/","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/wifisky7-rce.yaml","https://s4e.io/tools/wifisky-7-layer-flow-control-router-remote-code-execution","https://vulncheck.com/advisories/wifisky-flow-control-router-rce","https://www.cnvd.org.cn/flaw/show/CNVD-2021-45363","https://www.variotdbs.pl/vuln/VAR-202107-1715/"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV4_0":{"score":9.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"d9ec6823-d6ed-4fbb-8651-81062326db2e"},{"created":"2025-06-27T14:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"fa2b81e5-ef4e-427a-a594-c19173fb3b5c"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.0019},"old":{"score":0.0012}}}},"type":"metrics"}],"id":"fbe5c5af-db0b-4d9a-95a1-c747e7c6ed64"},{"created":"2025-11-17T21:30:00+00:00","data":[{"details":{"new":"A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-25 UTC.","old":"A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands."},"type":"description"}],"id":"a34b65e2-d059-4679-8016-e017c510702e"},{"created":"2025-11-17T22:30:00+00:00","data":[{"details":{"added":[],"removed":["CWE-20"]},"type":"weaknesses"}],"id":"e6419ccd-b0a1-4758-81c7-c2514abfe497"}],"cpes":{"data":[],"providers":[]},"created":{"data":"2025-06-26T15:51:30.957000+00:00","provider":"mitre"},"description":{"data":"A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-25 UTC.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{"score":9.4,"vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"},"provider":"mitre"},"epss":{"data":{"score":0.03831},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://www.szwifisky.com/","https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/other/wifisky7-rce.yaml","https://s4e.io/tools/wifisky-7-layer-flow-control-router-remote-code-execution","https://vulncheck.com/advisories/wifisky-flow-control-router-rce","https://www.cnvd.org.cn/flaw/show/CNVD-2021-45363","https://www.variotdbs.pl/vuln/VAR-202107-1715/"],"providers":["mitre","nvd"]},"title":{"data":"WIFISKY 7-Layer Flow Control Router Remote Command Execution","provider":"mitre"},"updated":{"data":"2026-04-15T00:35:42.020000+00:00","provider":"nvd"},"vendors":{"data":[],"providers":[]},"weaknesses":{"data":["CWE-78"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2025-06-26T15:51:30.957000+00:00","description":"A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-25 UTC.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"WIFISKY 7-Layer Flow Control Router Remote Command Execution","updated":"2025-06-27T13:34:49.979000+00:00","vendors":[],"vulnrichment_repo_path":"2025/34xxx/CVE-2025-34044.json","weaknesses":[]}}