TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply crafted values to execute arbitrary operating system commands as root, resulting in full device compromise.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 19 Nov 2025 18:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Nov 2025 01:30:00 +0900

Type Values Removed Values Added
First Time appeared Tg8
Tg8 tg8 Firewall
CPEs cpe:2.3:a:tg8:tg8_firewall:-:*:*:*:*:*:*:*
Vendors & Products Tg8
Tg8 tg8 Firewall

Sun, 16 Nov 2025 07:15:00 +0900

Type Values Removed Values Added
First Time appeared Togrow
Togrow tg8 Firewall
Vendors & Products Togrow
Togrow tg8 Firewall

Sat, 15 Nov 2025 08:00:00 +0900

Type Values Removed Values Added
Description TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply crafted values to execute arbitrary operating system commands as root, resulting in full device compromise.
Title TG8 Firewall Unauthenticated RCE via runphpcmd.php
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-18T16:20:30.649Z

Reserved: 2025-11-14T20:52:09.108Z

Link: CVE-2021-4470

cve-icon Vulnrichment

Updated: 2025-11-18T16:20:21.654Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-14T23:15:43.087

Modified: 2025-11-18T17:15:57.330

Link: CVE-2021-4470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-16T07:07:38Z

Weaknesses