Back to Database
Status published
Critical
CVE-2025-6559
Sapido Wireless Router - OS Command Injection
Vulnerability Description
Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The affected models are out of support; replacing the device is recommended.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6559
Credits & Attribution
No credits recorded in the NVD database.
References
More from Sapido
View All →CVE-2025-7554
Sapido RB-1802 URL Filtering Page urlfilter.asp cross site scripting
Medium
4.8
CVE-2025-6560
Sapido Wireless Router - Exposure of Sensitive Information
Critical
9.3
CVE-2021-4242
Sapido BR270n/BRC76n/GR297/RB1732 syscmd.htm os command injection
Medium
6.3
CVE-2019-25487
SAPIDO RB-1732 V2.0.43 Remote Command Execution via formSysCmd
Critical
9.3
Affected Vendor
Sapido
View all reports →Affected Software
BR071n, BR261c, BR270n, BR476n, BRC70n, BRC70x, BRC76n, BRD70n, BRE70n, BRE71n, BRF61c, BRF71n
Vulnerable Versions:
0
Timeline
Official Publish:
June 24th, 2025
Last Modified:
June 24th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H