CVE-2019-25289 is an authenticated remote command injection vulnerability affecting SmartLiving SmartLAN devices running firmware versions 6.x and earlier. Attackers can exploit an unsanitized 'par' POST parameter within the web.cgi binary, specifically with the 'testemail' module, to execute arbitrary system commands with root privileges using default credentials. This vulnerability carries a CVSS score of 8.8 (High), indicating a network-based attack with low complexity and high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 90/100 highlights its significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| INIM Electronics S.R.L. | SmartLiving SmartLAN/G/SI | 10100L, 10100L/G3, 1050, 1050/G3, 505, 515, <=6.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.