← Vulnerability feed

Vulnerability record · CVE-2025-54401 · published 7 October 2025

CVE-2025-54401: Planet wgr-500 firmware stack-based buffer overflow vulnerability

Planet · Wgr 500 Firmware

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the `submit-url` request parameter.

8.8 CVSS 3.1 High EPSS 0.73% · top 47.5% CWE-121 · Stack-based buffer overflow
8.8CVSS 3.1 base score
0.73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the `submit-url` request parameter.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54401 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-54403Planet wgr-500 firmware os command injection vulnerabilityMultiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request…EPSS 4.6%8.8CVE-2025-54404Planet wgr-500 firmware os command injection vulnerabilityMultiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request…EPSS 4.6%8.8CVE-2025-54405Planet wgr-500 firmware os command injection vulnerabilityMultiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of …EPSS 4.3%8.8CVE-2025-54406Planet wgr-500 firmware os command injection vulnerabilityMultiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of …EPSS 4.3%8.8CVE-2025-54399Planet wgr-500 firmware stack-based buffer overflow vulnerabilityMultiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted ser…EPSS 0.77%8.8CVE-2025-54400Planet wgr-500 firmware stack-based buffer overflow vulnerabilityMultiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted ser…EPSS 0.73%8.8CVE-2025-54402Planet wgr-500 firmware stack-based buffer overflow vulnerabilityMultiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted ser…EPSS 0.77%8.8CVE-2025-48826Planet wgr-500 firmware vulnerabilityA format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests c…EPSS 6.9%

Source: NIST National Vulnerability Database (record CVE-2025-54401), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.