
CVE-2025-8890 Authenticated RCE in SDMC NE6037 router
When testing connectivity of the SDMC NE6037 router inputting a quote character into the "ping" utility revealed an error indicating a Remote Code Execution (RCE) vulnerability. It is quite common to find RCE vulnerabilities in routers’ connectivity tools (such as ping or traceroute). The user-supplied parameters are passed without sanitization as a parameter to a shell command. This was confirmed to be the root cause in this instance.




![Illustration of Comparison of reverse image searching in popular search engines [OSINT hints]](https://securitum.com/images/ilustration-web-application-png-1692958812534.webp)







