GHSA-cgfg-qq46-f464 · Severity: medium — A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. Impacted is the...
A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. Impacted is the function action_ipsec_conn of the file /usr/bin/lib/lua/luci/controller/ipsec.lua. Executing a manipulation can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading the affected component is advised. The vendor explains, that "some other customer has reported this to us before. And we have fixed this."
Conclusion & alert: CVE-2026-4537 is rated Low Risk (27.5/100): CVSS Low severity, with medium exploitation likelihood (EPSS 0.32%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-28 | 0.23% | 0.32% | +0.09% |
| 2 | 2026-03-22 | — | 0.23% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 2.0 | 4.0 | LOW |
|
— | — | [email protected] |
| 4.7 | 3.1 | MEDIUM |
|
1.2 | 3.4 | [email protected] |
| 5.8 | 2.0 | MEDIUM |
|
6.4 | 6.4 | [email protected] |
GHSA-cgfg-qq46-f464 · Severity: medium — A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. Impacted is the...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||