CVE-2025-58428Critical· 9.9▾ MidnightThe TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Li…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.4%
The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12313Medium· 6.3A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1
CVE-2025-13562High· 7.3A vulnerability was identified in D-Link DIR-852 1.00
CVE-2025-14225Medium· 6.3A vulnerability was determined in D-Link DCS-930L 1.15.04
CVE-2025-14707Critical· 9.8A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14706Critical· 9.8A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25
CVE-2025-14705Critical· 9.8A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25