← back
CVE-2025-27797criticalCWE-78

CVE-2025-27797

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 1.0%
exploitation probability
1.0%top 42% of all CVEs
observed exploitation
nono source reports it
In short

A Wi-Fi access point (AC-WPS-11ac series) allows attackers who log in to execute any operating system command they want. This bypasses normal security controls and gives complete control of the device.

Technical detail

OS command injection vulnerability (CWE-78) in AC-WPS-11ac Wi-Fi AP service allows authenticated remote attackers to execute arbitrary OS commands through unsanitized input. Attack vector requires valid login credentials; successful exploitation grants full system-level access and control over the affected device.

Summary generated and translated by AI from the official description.
OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to the product.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H