---
id: CVE-2025-14704
title: A vulnerability was found in Shiguangwu sgwbox N3 2.0.25
summary: >-
  A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element
  is an unknown function of the file /eshell of the component API. The
  manipulation results in path traversal. It is possible to launch the attack
  remotely. The…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-22
vendor: sgwbox
product: n3_firmware
affected:
  - n3_firmware <= 2.0.25
published: '2025-12-15'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14704'
references:
  - url: 'https://vuldb.com/?ctiid.336421'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.336421'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.706915'
    label: cna@vuldb.com
  - url: >-
      https://www.notion.so/sgwbox-NAS-N3-Directory-Traversal-2be6cf4e528a802a9c0ad6f01b75694e?source=copy_link
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.12488
epssPercentile: 0.96119
ingestedAt: '2026-10-07T19:44:15.677Z'
---

## Overview

A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The manipulation results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `n3_firmware <= 2.0.25`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
