[Vulnerability Alert] Two Critical Security Vulnerabilities Found in Sapido Technology Wireless Routers

publish date : 2025-07-04 update date : 2025-07-04

Source: Ministry of education information & communication security contingency platform

Publication Number TACERT-ANA-2025062401060707 Publication Time 2025/06/24 13:57
Incident Type ANA-Vulnerability Alert Discovery Time 2025/06/24 13:57
Impact Level Low  
[Subject]
[Vulnerability Alert] Two Critical Security Vulnerabilities Found in Sapido Technology Wireless Routers
[Content]
Forwarded from TWCERTCC-200-202506-00000016

[Sapido Wireless Routers – OS Command Injection] (CVE-2025-6559, CVSS: 9.8)
Multiple models of Sapido Technology wireless routers contain an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the device.

[Sapido Wireless Routers – Exposure of Sensitive Information] (CVE-2025-6560, CVSS: 9.8)
Some models of Sapido Technology wireless routers have a vulnerability that exposes sensitive information. Unauthenticated remote attackers can directly access configuration files and retrieve plaintext administrator usernames and passwords.

Information Sharing Level: WHITE (Information content can be publicly disclosed)
[Affected Platform]
BR071n, BR261c, BR270n, BR476n, BRC70n, BRC70x, BRC76n, BRD70n, BRE70n, BRE71n, BRF61c, BRF71n
[Recommended Actions]
These affected models are no longer maintained. It is recommended to replace the devices.
[Reference]
Sapido Wireless Routers – OS Command Injection
https://www.twcert.org.tw/tw/cp-132-10196-898d3-1.html

Sapido Wireless Routers – Exposure of Sensitive Information
https://www.twcert.org.tw/tw/cp-132-10197-524ea-1.html
(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center