๐Ÿ” CVE Alert

CVE-2025-67113

CRITICAL 9.8
CVSS Score
9.8
EPSS Score
0.1%
EPSS Percentile
28th

OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary commands as root via a crafted TR-069 Download URL that is passed unescaped into the firmware upgrade pipeline.

Vendor n/a
Product n/a
Published Mar 19, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new critical vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
neroteam.com: https://neroteam.com/blog/freedomfi-sercomm-sce4255w-englewood fcc.report: https://fcc.report/FCC-ID/P27-SCE4255W/4790935.pdf freedomfi.com: https://freedomfi.com/index.html