A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented. An unauthenticated remote attacker can send specially crafted UDP packets to execute arbitrary commands on the affected device. This backdoor uses a hardcoded authentication mechanism and accepts shell commands post-authentication. Some device models include a non-standard implementation of the `echo` command, which may affect exploitability.
                
            CVSS
                No CVSS.
References
                    Configurations
                    No configuration.
History
                    17 Jul 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
16 Jul 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-07-16 21:15
Updated : 2025-07-17 21:15
NVD link : CVE-2025-34117
Mitre link : CVE-2025-34117
CVE.ORG link : CVE-2025-34117
JSON object : View
Products Affected
                No product.
