logo

Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts

ID: da781e74-e3a5-5146-b78f-e40632c76393

STIX ID: report--da781e74-e3a5-5146-b78f-e40632c76393

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-30

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Executive summary:** A critical unauthenticated zero-day (CVE-2025-54322) in XSpeeder SXZOS allows remote root RCE via a crafted HTTP GET request that evals base64-decoded Python in a vulnerable Django endpoint; over 70,000 devices (SD-WAN, edge routers, smart TV controllers) are exposed globally, the vendor has not responded to disclosure, and administrators are advised to segment networks, restrict management access, and monitor for exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.