Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21423 | An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling in the undocumented /cgi-bin/rdfs.cgi endpoint. The Client parameter is not sanitized before being passed to a system call, allowing an unauthenticated remote attacker to execute arbitrary commands as the web server user. |
Fri, 21 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Barco
Barco wepresent Wipg-1000p Firmware |
|
| CPEs | cpe:2.3:a:barco:wepresent_wipg-1000p_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Barco
Barco wepresent Wipg-1000p Firmware |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Tue, 15 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling in the undocumented /cgi-bin/rdfs.cgi endpoint. The Client parameter is not sanitized before being passed to a system call, allowing an unauthenticated remote attacker to execute arbitrary commands as the web server user. | |
| Title | WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi | |
| Weaknesses | CWE-306 CWE-78 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T11:14:40.949Z
Reserved: 2025-04-15T19:15:22.556Z
Link: CVE-2025-34103
Updated: 2025-07-15T13:31:25.224Z
Status : Deferred
Published: 2025-07-15T13:15:29.820
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-34103
No data.
OpenCVE Enrichment
Updated: 2026-05-11T17:30:15Z
EUVD