OS command injection in the CWMP client (/ftl/bin/cwmp)...
Critical severity
Unreviewed
Published
Mar 19, 2026
to the GitHub Advisory Database
•
Updated Mar 24, 2026
Description
Published by the National Vulnerability Database
Mar 19, 2026
Published to the GitHub Advisory Database
Mar 19, 2026
Last updated
Mar 24, 2026
OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers controlling the ACS endpoint to execute arbitrary commands as root via a crafted TR-069 Download URL that is passed unescaped into the firmware upgrade pipeline.
References