CVE-2019-25289: Inim Electronics S.r.l Smartliving Smartlan/g/si

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

SmartLiving SmartLAN <=6.x contains an authenticated remote command injection vulnerability in the web.cgi binary through the 'par' POST parameter with the 'testemail' module. Attackers can exploit the unsanitized parameter and system() function call to execute arbitrary system commands with root privileges using default credentials.

Affected products

  • Inim Electronics S.r.l Smartliving Smartlan/g/si: up to and including 6.0; version 505 only; version 515 only; version 1050 only; version 10100L only

Published 2026-01-08. Last modified 2026-06-17.