OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary commands as root via a crafted TR-069 Download URL that is passed unescaped into the firmware upgrade pipeline.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Mar 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freedomfi
Freedomfi sercomm Sce4255w |
|
| Vendors & Products |
Freedomfi
Freedomfi sercomm Sce4255w |
Thu, 19 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary commands as root via a crafted TR-069 Download URL that is passed unescaped into the firmware upgrade pipeline. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-19T17:26:38.767Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-67113
No data.
Status : Received
Published: 2026-03-19T18:16:15.600
Modified: 2026-03-19T18:16:15.600
Link: CVE-2025-67113
No data.
OpenCVE Enrichment
Updated: 2026-03-20T08:58:05Z
Weaknesses
No weakness.