ZeroHour

CVE-2025-34117

mass

Backdoor Listener Enables Unauthenticated RCE in Netcore and Netis Routers

CVSS 4.0
9.3 critical
EPSS
28%p98
Published
()
Modified
AI analysis

Multiple Netcore and Netis router models ship with an undocumented, hardcoded backdoor listening on UDP port 53413, present in all firmware released prior to August 2014. An unauthenticated remote attacker can send specially crafted UDP packets to this listener, pass the hardcoded authentication mechanism, and execute arbitrary shell commands on the device. Successful exploitation gives the attacker full control of the router (device confidentiality, integrity, and availability are all rated high), which can be used for traffic interception, botnet enlistment, or pivoting to internal networks. All Netcore and Netis routers running pre-August 2014 firmware are affected, though exact version boundaries are undocumented and a non-standard `echo` implementation on some models may affect exploitability. No public proof-of-concept or CISA KEV listing is known at this time, but the 27.9% EPSS score (98th percentile) indicates an elevated probability of exploitation within 30 days.

What to do: Audit internet-facing router IPs for UDP port 53413 and block or restrict that port at the network perimeter as an immediate mitigation, since exploitation requires reaching the listener. Upgrade affected devices to firmware released after August 2014, or current vendor firmware where available; because exact version boundaries are undocumented, verification by probing UDP/53413 is the most reliable check. For Netcore/Netis routers that are end-of-life and cannot receive patched firmware, replacement should be considered, as hardcoded-backdoor flaws cannot be fully mitigated by filtering alone.

Affected
Netcore Routers (multiple models) with undocumented UDP 53413 backdoor listenerAll firmware released prior to August 2014 (exact version boundaries undocumented)
Netis Routers (multiple models) with undocumented UDP 53413 backdoor listenerAll firmware released prior to August 2014 (exact version boundaries undocumented)
Estimated exposure
mass≈1–2 million internet-exposed routers (order-of-magnitude estimate from public internet-wide scans of UDP/53413) — Internet-wide scans publicized when this backdoor was disclosed in 2014 found on the order of one to two million devices with UDP port 53413 reachable, and consumer routers of this age are frequently never patched, so a large fraction of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due to the presence of an undocumented backdoor listener on UDP port 53413. Exact version boundaries remain undocumented. An unauthenticated remote attacker can send specially crafted UDP packets to execute arbitrary commands on the affected device. This backdoor uses a hardcoded authentication mechanism and accepts shell commands post-authentication. Some device models include a non-standard implementation of the `echo` command, which may affect exploitability.

Weakness
CWE-78, CWE-306, CWE-912
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.