CVE-2025-8890 CRITICAL

CVE-2025-8890: Authenticated RCE in SDMC NE6037 router

Vendor Sdmc
Product NE6037
Weakness CWE-78
Published November 27, 2025
Last update March 18, 2026

CVSS base score

9.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks. In order to exploit this vulnerability, an attacker has to log in to the router's administrative portal, which by default is reachable only via LAN ports.

Key dates

02Disclosure timeline

November 27, 2025 CVE published
March 18, 2026 Record updated