CVE-2025-14708 describes a buffer overflow vulnerability in Shiguangwu sgwbox N3 2.0.25, specifically within the WIREDCFGGET Interface's /usr/sbin/http_eshell_server component. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated remote attacker to cause a denial of service by manipulating the 'params' argument. Public exploit code is available, and the vendor has not responded to disclosure, increasing the risk of exploitation. While not currently in CISA KEV, community discussion indicates awareness of this critical flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.25CPE matchmatch criteria | cpe:2.3:o:sgwbox:n3_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.