A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://certvde.com/de/advisories/VDE-2025-058 |
![]() ![]() |
History
Mon, 21 Jul 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Jul 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. | |
Title | Remote Command Injection in diagnostic Action Due to Improper Input Neutralization | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-07-21T09:29:43.181Z
Updated: 2025-07-21T17:05:33.656Z
Reserved: 2025-04-16T11:17:48.308Z
Link: CVE-2025-41674

Updated: 2025-07-21T17:05:29.383Z

Status : Awaiting Analysis
Published: 2025-07-21T10:15:24.363
Modified: 2025-07-22T13:06:07.260
Link: CVE-2025-41674

No data.