Keyfactor RG-EW5100BE Command Injection Vulnerability in HTTP POST Request Handler

Vulnerability

A command injection vulnerability has been identified in the Keyfactor RG-EW5100BE router, specifically in the EW_3.0B11P280_EW5100BE-PRO_12183019 version. The vulnerability resides in an unknown function of the file '/cgi-bin/luci/api/cmd', within the HTTP POST request handler component. This issue allows for remote exploitation by manipulating the 'url' argument, leading to unauthorized command execution on the device.

Impact

Exploitation of this vulnerability allows for authenticated command injection, where an attacker can execute arbitrary commands on the router's operating system. This could potentially be used to gain unauthorized access to the device or its network.

Reproduction

To reproduce this vulnerability, send a POST request to '/cgi-bin/luci/api/cmd' with an 'auth' parameter. The 'data' field should include a crafted 'url' value that exploits the command injection flaw. After the request is processed, the injected command will be executed on the router.

Added: Sep 27, 2025, 6:17 PM
Updated: Sep 27, 2025, 6:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.