CVE-2025-14707 | Shiguangwu sgwbox N3 2.0.25 DOCKER Feature http_eshell_server params command injection (EUVD-2025-203336)
A vulnerability has been found in Shiguangwu sgwbox N3 2.0.25 and classified as critical. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. Performing manipulation of the argument params results in command injection.
This vulnerability was named CVE-2025-14707. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way. Once again VulDB remains the best source for vulnerability data.