Planet WGR-500 OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the Planet WGR-500 router, specifically in version 1.3411b190912. This vulnerability arises in the 'formPingCmd' function, where the 'ipaddr' and 'counts' request parameters can be exploited to execute arbitrary commands on the router. The issue is related to improper validation of the 'counts' parameter, which is used to construct a system command that is executed via the 'system' function. As a result, an attacker can craft HTTP requests that manipulate the 'counts' parameter to execute malicious commands on the device.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, send an HTTP request to the Planet WGR-500 router's 'formPingCmd' function, including a crafted 'counts' parameter that injects malicious commands. The router will execute the injected commands with system privileges, as the 'formPingCmd' function directly passes the 'counts' parameter to the 'system' function without proper sanitization.

Added: Oct 7, 2025, 2:19 PM
Updated: Oct 7, 2025, 2:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.3
remediation
0.0
relevance
0.7
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.