๐Ÿ” CVE Alert

CVE-2025-71284

CRITICAL 9.8

Synway SMG Gateway Management Software OS Command Injection via radius_address

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. An unauthenticated remote attacker can inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC).

CWE CWE-78
Vendor synway information engineering co., ltd.
Product synway smg gateway management software
Published Apr 30, 2026
Stay Ahead of the Next One

Get instant alerts for synway information engineering co., ltd. synway smg gateway management software

Be the first to know when new critical vulnerabilities affecting synway information engineering co., ltd. synway smg gateway management software are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Synway Information Engineering Co., Ltd. / Synway SMG Gateway Management Software
0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/projectdiscovery/nuclei-templates/blob/main/http/vulnerabilities/synway/synwaysmg-radius-rce.yaml mrxn.net: https://mrxn.net/jswz/synway-9-2radius-rce.html mp.weixin.qq.com: https://mp.weixin.qq.com/s/PyepoFSuQ63E3RnpQa9nsA synway.net: https://www.synway.net/ vulncheck.com: https://www.vulncheck.com/advisories/synway-smg-gateway-management-software-os-command-injection-via-radius-address

Credits

The Shadowserver Foundation