CVE-2025-71284Disclosure(synway / smg_gateway_management_software)

MEDIUMCVSS 9.3 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch synway smg_gateway_management_software systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and interpolated directly into a sed command without sanitization. An unauthenticated remote attacker can inject arbitrary shell commands by submitting a POST request with crafted radius_address, radius_address2, shared_secret2, source_ip, timeout, or retry parameters along with save=1 and enable_radius=1 to achieve remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-11 (UTC).

4.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • smg_gateway_management_software

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 5 mentions (2026-04-30); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
smg_gateway_management_software

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-30: 5Mentions · 2026-05-04: 1Active Exploitation · 2026-05-04: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-04: 1Technical Details · 2026-04-30: 5Technical Details · 2026-05-04: 104-3005-04
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-305
Disclosure4Patch1
2026-05-041
Active Exploitation1
Full discourse6 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-71284 — CVSS 9.8/10 ██████████ Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/05pxPNN9hg

    Post summary

    The tweet alerts to a critical OS command injection vulnerability in Synway SMG Gateway Management Software and urges users to apply the available patch.

    20000722
    25 followersView on X
  • Modat@modat_magnify
    Active Exploitation

    CVE-2025-71284  ⚠️ Synway SMG Gateways – Unauthenticated RCE (CVSS 9.8)  A critical OS command injection in Synway SMG gateways allows unauthenticated attackers to execute arbitrary commands via /en/9-2radius.php, where unsanitised POST parameters are passed directly into a sed command, enabling remote code execution. Exposed devices risk full takeover, telecom fraud, SMS phishing, and persistent access at the network edge.  The flaw has been actively exploited since July 2025, leaving defenders blind to ongoing abuse for 10 months before a CVE was assigned. No patch available.  Mitigation: Remove internet exposure immediately and restrict access to trusted internal IPs only.  Modat Magnify Query: 
(web.title="IPPBX" or web.html~"synwayjs") OR (web.html~"text ml10 mr20" and (web.title="网关管理软件" or web.title~"Gateway Management")) and tag!="Honeypot"  The platform: https://magnify.modat.io #threatintel #vulnerability #CVE202571284 #RCE #VoIP #Telecom #infosec #Critical #ModatMagnify

    Post summary

    The CVE-2025-71284 vulnerability in Synway SMG gateways has been actively exploited since July 2025, with no patch available, requiring immediate mitigation by restricting external access.

    000001.0K
    429 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-71284 Unauthenticated Remote Code Execution via OS Command Injection in Synway SMG Gateway Management Software https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-71284

    Post summary

    This brief entry announces CVE‑2025‑71284, a new unauthenticated RCE flaw via OS command injection in Synway SMG Gateway Management Software, without providing PoC, exploit, or patch details.

    00000484
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-71284 Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_addre… https://www.cve.org/CVERecord?id=CVE-2025-71284 ----- Traducción: CVE-2025-71284 Syn… http://infoflow.cloud`

    Post summary

    CVE-2025-71284 is an OS command injection flaw in Synway SMG Gateway Management Software’s RADIUS configuration endpoint, with no reported exploits, patches, or active attacks.

    00000746
    74 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-71284 Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_addre… https://www.cve.org/CVERecord?id=CVE-2025-71284

    Post summary

    The CVE-2025-71284 report discloses an OS command injection flaw in Synway SMG Gateway Management Software’s RADIUS configuration endpoint, but it does not provide proof of concept, exploit code, active exploitation evidence, or a patch.

    00000439
    57.3K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2025-71284 Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpo… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2025-71284 #HP #CyberSecurity #InfoSec

    Post summary

    The post announces CVE‑2025‑71284, an OS command injection in Synway SMG Gateway Management Software with CVSS 9.8, noting that no patch is available yet.

    00000622
    256 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsynwaysmg_gateway_management_software---

Explore more