Shiguangwu sgwbox N3 Command Injection

CRITICAL (9.8) No Patch

Threat Intelligence

Low Risk
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

Shiguangwu sgwbox N3 is a proprietary HR software used by some organizations for employee management. This vulnerability allows attackers to inject malicious commands on the server without any authentication or user interaction, potentially leading to unauthorized access to sensitive data.

Am I affected?

You're affected if you use A vulnerability was determined. Specific version info not stated in the advisory. If you don't recognise this software, you're probably not affected.

Affected Products

aEnrich / sgwbox N3

How to fix

Contact aEnrich directly for a patched version - there's no public patch link in the advisory.
Immediate mitigations:
- Restrict network access to your sgwbox N3 instance (firewall it from the public internet)
- Audit admin account activity for suspicious access patterns
- Monitor for unauthorized token creation