CVE-2025-48890 is a critical OS Command Injection vulnerability (CWE-78) affecting ELECOM WRH-733GBK and WRH-733GWH routers via their miniigd SOAP service. This flaw allows a remote, unauthenticated attacker to execute arbitrary operating system commands by sending a specially crafted request. With a CVSS score of 9.8 (Critical), the vulnerability poses a significant risk of complete compromise (confidentiality, integrity, and availability). While there is no known active exploitation or publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered some community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ELECOM CO.,LTD. | WRH-733GBK | all versionsCNA affected | |
| ELECOM CO.,LTD. | WRH-733GWH | all versionsCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.