Source: Ministry of education information & communication security contingency platform
Publication Number | TACERT-ANA-2025062401060707 | Publication Time | 2025/06/24 13:57 |
Incident Type | ANA-Vulnerability Alert | Discovery Time | 2025/06/24 13:57 |
Impact Level | Low | ||
[Subject] [Vulnerability Alert] Two Critical Security Vulnerabilities Found in Sapido Technology Wireless Routers |
|||
[Content] Forwarded from TWCERTCC-200-202506-00000016 [Sapido Wireless Routers – OS Command Injection] (CVE-2025-6559, CVSS: 9.8) Multiple models of Sapido Technology wireless routers contain an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the device. [Sapido Wireless Routers – Exposure of Sensitive Information] (CVE-2025-6560, CVSS: 9.8) Some models of Sapido Technology wireless routers have a vulnerability that exposes sensitive information. Unauthenticated remote attackers can directly access configuration files and retrieve plaintext administrator usernames and passwords. Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
[Affected Platform] BR071n, BR261c, BR270n, BR476n, BRC70n, BRC70x, BRC76n, BRD70n, BRE70n, BRE71n, BRF61c, BRF71n |
|||
[Recommended Actions] These affected models are no longer maintained. It is recommended to replace the devices. |
|||
[Reference] Sapido Wireless Routers – OS Command Injection https://www.twcert.org.tw/tw/cp-132-10196-898d3-1.html Sapido Wireless Routers – Exposure of Sensitive Information https://www.twcert.org.tw/tw/cp-132-10197-524ea-1.html |