THREATPORT/VULNERABILITY/CVE-2025-34103
HIGH SEVERITY

CVE-2025-34103

CVE-2025-34103 vulnerability

Severity
HIGH
EPSS
4.2%
EPSS pct
90th
Exploited
No known
An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling in the undocumented /cgi-bin/rdfs.cgi endpoint. The Client parameter is not sanitized before being passed to a system call, allowing an unauthenticated remote attacker to execute arbitrary commands as the web server user.
Affected vendor
See references
Affected product
See references
Weakness type (CWE)
  • CWE-78 — OS Command Injection
  • CWE-306 — Missing Authentication for Critical Function
Published
2025-07-15

Risk analysis

Its EPSS score of 4.2% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 90% of all scored CVEs.

Check your external exposure to CVE-2025-34103

  • Confirm whether the affected software is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2025-34103.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2025-34103

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2025-34103 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2025-34103?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2025-34103.

Start free scan

No credit card. Agentless.