| CVE ID | CVE-2025-8890 |
| Publication date | 27 November 2025 |
| Vendor | SDMC |
| Product | NE6037 |
| Vulnerable versions | All before 7.1.12.2.44 |
| Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in SDMC NE6037 firmware and participated in coordination of its disclosure.
The vulnerability CVE-2025-8890: Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks. In order to exploit this vulnerability, an attacker has to log in to the router's administrative portal, which by default is reachable only via LAN ports.
Credits
We thank Grzegorz Bronka from Securitum.pl for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.