CVE-2025-43953

High severity, CVSS 8.8. EPSS: 7.6% chance of exploitation in the next 30 days.

In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or traceroute field on the TCP/IP screen.

Published 2025-09-22. Last modified 2026-06-17.