ZeroHour

CVE-2025-3002

niche

OS Command Injection in Digital China DCME-520 (CVE-2025-3002)

CVSS 4.0
6.9 medium
EPSS
20%p97
Published
()
Modified
AI analysis

Digital China's DCME-520 contains an OS command injection flaw (CWE-77/CWE-78) in the script /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php, where the type_name parameter is passed to the operating system without adequate validation. The attack can be launched remotely over the network and requires no privileges or user interaction per the CVSS scoring, and other parameters in the affected script may also be vulnerable. An attacker who successfully exploits the flaw can inject and execute arbitrary operating system commands on the controller, potentially giving them control of the device and a foothold in the network it manages. Affected are DCME-520 deployments with firmware up to the 20250320 build; other DCME products are not confirmed in the available data. The exploit has been publicly disclosed and, with an EPSS of 20% (97th percentile), there is an elevated probability of exploitation in the next 30 days, though the flaw is not yet on the CISA KEV list and no public PoC code is catalogued.

What to do: Because no fixed version is published in the available data, contact Digital China or your reseller for a patched firmware for the DCME-520. In the meantime, restrict web-based management access to the controller (including the /usr/local/WWW/function/audit/newstatistics/ endpoint) to trusted management networks and disable internet-exposed management if possible. Check device logs for unexpected process executions or requests containing crafted type_name values to detect exploitation attempts.

Affected
Digital China DCME-520up to 20250320 (firmware/builds through 2025-03-20)
Estimated exposure
nichelikely low thousands of controllers (China-market enterprise WLAN controller; no public install-base or internet-exposure data available) — The DCME-520 is an enterprise wireless access controller sold primarily in Chinese enterprise and campus networks, a product class typically deployed in low thousands rather than mass-scale consumer volumes, so the estimate is based on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.