SAPIDO RB-1732 Remote Command Execution Vulnerability

Vulnerability

A remote command execution vulnerability exists in the SAPIDO RB-1732 router, specifically in version 2.0.43. This vulnerability allows unauthenticated attackers to execute arbitrary system commands by sending malicious input to the formSysCmd endpoint. Exploitation involves POST requests with the sysCmd parameter containing shell commands, which are executed on the device with router privileges.

Impact

Exploitation of this vulnerability allows for remote command execution on the affected device with router privileges.

Reproduction

To reproduce this vulnerability, send a POST request to the '/goform/formSysCmd' endpoint. Include the sysCmd parameter with the desired shell command. The command will be executed on the device, and the output can be retrieved from the response.

Added: Mar 11, 2026, 7:32 PM
Updated: Mar 11, 2026, 7:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
9.1
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.