Critical 0-Day RCE Flaw in Networking Devices Exposes Over 70,000 Hosts
ID: 832126e2-660d-5cea-a55c-3604478bc312
STIX ID: report--832126e2-660d-5cea-a55c-3604478bc312
Feed Name: Cyber Press
A critical unauthenticated RCE (CVE-2025-54322) in XSpeeder SXZOS devices allows attackers to execute arbitrary Python code as root by abusing an unsafe eval() of base64-decoded query parameters; researchers validated firmware and live exploitation and estimate ~70,000 publicly reachable devices are affected, while the vendor has not responded or released patches — recommended mitigations include isolating devices, applying network-level access controls, and monitoring for exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
