A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session invalidation after administrator logout. When an administrator logs out, the session token remains valid. An attacker on the local network can reuse this stale token to send crafted requests via the router’s diagnostic endpoint, resulting in command execution as root.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 23 Dec 2025 09:30:00 +0900

Type Values Removed Values Added
First Time appeared Genexis platinum 4410
Genexis platinum 4410 Firmware
CPEs cpe:2.3:h:genexis:platinum_4410:-:*:*:*:*:*:*:*
cpe:2.3:o:genexis:platinum_4410_firmware:p4410-v2-1.41:*:*:*:*:*:*:*
Vendors & Products Genexis platinum 4410
Genexis platinum 4410 Firmware

Tue, 09 Dec 2025 01:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-613
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 20:00:00 +0900

Type Values Removed Values Added
First Time appeared Genexis
Genexis platinum
Genexis platinum P4410
Vendors & Products Genexis
Genexis platinum
Genexis platinum P4410

Fri, 05 Dec 2025 04:45:00 +0900

Type Values Removed Values Added
Description A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local network attacker to achieve Remote Code Execution (RCE) with root privileges. The issue occurs due to improper session invalidation after administrator logout. When an administrator logs out, the session token remains valid. An attacker on the local network can reuse this stale token to send crafted requests via the router’s diagnostic endpoint, resulting in command execution as root.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-08T16:04:02.641Z

Reserved: 2025-11-18T00:00:00.000Z

Link: CVE-2025-65883

cve-icon Vulnrichment

Updated: 2025-12-08T16:03:51.240Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-04T20:16:19.770

Modified: 2025-12-23T00:22:22.200

Link: CVE-2025-65883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-05T19:52:04Z

Weaknesses