Junglewise Threat Intelligence

CVE-2025-29269: ALLNET ALL-RUT22GW OS command injection in popen.cgi

CVE-2025-29269 · Severity: critical · CVSS 9.8 · Published 2025-12-04

Executive brief

The ALLNET ALL-RUT22GW is an industrial cellular router used for machine-to-machine communications and IoT applications in demanding environments. A critical security flaw allows an unauthenticated attacker to remotely take full control of the device by executing arbitrary commands with administrative (root) privileges. This could lead to complete service disruption, interception of industrial data, or the use of the router as a foothold to attack other systems on the network.

Technical details

An OS command injection vulnerability exists in the popen.cgi endpoint of the ALLNET ALL-RUT22GW industrial router running firmware version 3.3.8. The vulnerability is located in the handling of the 'command' GET parameter, which is passed directly to the popen() function and executed via /bin/sh without any sanitization or authentication checks. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to execute arbitrary commands with root privileges. This provides the attacker with complete control over the device's operating system and network traffic. At the time of reporting, no official patch has been confirmed, though the vulnerability was publicly disclosed with a Proof of Concept (PoC).

Affected products

  • ALLNET ALL-RUT22GW firmware 3.3.8
  • ALLNET ALL-RUT22GW -

Timeline

  • 2025-12-01: disclosed: Initial public disclosure by ByteRay researchers
  • 2025-12-04: advisory: CVE-2025-29269 published

References

Related threats