Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts

A critical zero-day vulnerability has been identified in XSpeeder's SXZOS firmware, impacting numerous SD-WAN appliances, edge routers, and smart TV controllers worldwide.

A critical zero-day vulnerability has been identified in XSpeeder's SXZOS firmware, impacting numerous SD-WAN appliances, edge routers, and smart TV controllers worldwide.

The vulnerability, known as PWN-25-01, permits unauthenticated remote code execution (RCE) with root-level access via a single HTTP GET request.

XSpeeder, a networking vendor based in China, produces SXZOS-based devices extensively used in remote industrial and branch settings.

Security experts at pwn.ai discovered this flaw through autonomous firmware analysis and multi-agent exploitation methods. This represents the first agent-discovered, remotely exploitable zero-day RCE that has been publicly disclosed.

The issue is located within XSpeeder's Django-based web application framework.

CVE/ID: CVE-2025-54322 Vendor: XSpeeder (SXZOS Firmware) Vulnerability Type: Pre-authentication Remote Code Execution CVSS Severity: Critical (9.8) Affected Devices: SD-WAN Appliances, Edge Routers, Smart TV Controllers Exposed Hosts: 70,000+ globally Authentication Required: No

A critical vulnerability was found in the /webInfos/ endpoint, which processes three query parameters without adequate input validation.

The vulnerability, known as PWN-25-01, permits unauthenticated remote code execution (RCE) with root-level access via a single HTTP GET request.
Leo Underwood · Thehackingpost

The affected code path employs eval() on base64-decoded user input, circumventing superficial middleware security layers intended to prevent unauthorized access.

Exploiting this flaw involves bypassing three defense mechanisms: a time-synchronized nonce header (X-SXZ-R), a session cookie warm-up requirement, and a simple substring filter that operates on pre-decoded data.

These defenses function at the middleware and Nginx layers, leaving the vulnerable view accessible when properly crafted requests meet these basic conditions.

Attackers can achieve full command execution by sending a specially formatted HTTP GET request that includes base64-encoded malicious Python code in the chkid parameter.

No authentication credentials are necessary, and the vulnerability affects all publicly accessible SXZOS devices on the internet.

According to Fofa and advanced fingerprinting services, more than 70,000 SXZOS-based systems remain exposed globally.

Advertisement

These devices manage critical infrastructure in industrial and branch office environments, making this vulnerability a significant risk for enterprises.

Despite over seven months of coordinated disclosure efforts, XSpeeder has not responded to pwn.ai security researchers.

This lack of response leads to disclosure in line with responsible vulnerability management protocols, leaving organizations without vendor-provided patches at the time of publication.

Administrators overseeing XSpeeder equipment should immediately implement network segmentation, restrict access to device management interfaces, and monitor for exploitation attempts.

Organizations are advised to consider alternative networking solutions until vendor patches become available.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories