Junglewise Threat Intelligence

CVE-2025-65753: Gryphon Guardian improper certificate validation in speedtest client download

CVE-2025-65753 · Severity: high · CVSS 7.5 · Published 2026-02-17

Executive brief

The Gryphon Guardian is a WiFi access point and router designed for home network security and parental controls. A vulnerability in how the device handles software updates for its speed test utility allows an attacker to intercept the connection and replace legitimate software with malicious code. If exploited, an attacker can gain full administrative (root) control over the router, potentially allowing them to monitor network traffic or disable security features.

Technical details

The vulnerability exists in the TLS certification mechanism of the Gryphon Guardian firmware (v01.06.0006.22) during the download of the 'ookla-speedtest' CLI client. The device fails to properly validate the authenticity of the TLS certificate (CWE-295), accepting self-signed certificates. An attacker positioned as a Man-in-the-Middle (MitM) or capable of DNS spoofing can redirect the request for the speed test tarball to a malicious server. Because the downloaded binary is automatically extracted and executed with root privileges, the attacker can achieve full remote code execution (RCE) on the device. Exploitation requires the user to trigger a speed test via the mobile app while the attacker intercepts the network traffic.

Affected products

  • Gryphon Guardian Gryphon 01.06.0006.22

Timeline

  • 2026-02-17: advisory: Initial disclosure and NVD publication

References