CVE-2025-34044: Shenzhen Lingkong Technology Wifisky 7-Layer Flow Control Router

Critical severity, CVSS 9.4. EPSS: 3.9% chance of exploitation in the next 30 days.

A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-25 UTC.

Affected products

Published 2025-06-26. Last modified 2026-06-17.