Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts
ID: da781e74-e3a5-5146-b78f-e40632c76393
STIX ID: report--da781e74-e3a5-5146-b78f-e40632c76393
Feed Name: cybersecurityNews.com
Threat Score
**Executive summary:** A critical unauthenticated zero-day (CVE-2025-54322) in XSpeeder SXZOS allows remote root RCE via a crafted HTTP GET request that evals base64-decoded Python in a vulnerable Django endpoint; over 70,000 devices (SD-WAN, edge routers, smart TV controllers) are exposed globally, the vendor has not responded to disclosure, and administrators are advised to segment networks, restrict management access, and monitor for exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
