WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path traversal in the showerr script.
This issue was fixed in version 6.44.44
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path traversal in the showerr script. This issue was fixed in version 6.44.44 | |
| Title | OS Command Injection via Path Traversal in WaveStore Server | |
| Weaknesses | CWE-22 CWE-78 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-12-16T14:38:42.175Z
Reserved: 2025-11-17T09:20:09.472Z
Link: CVE-2025-65074
No data.
Status : Awaiting Analysis
Published: 2025-12-16T13:15:57.887
Modified: 2025-12-16T14:10:11.300
Link: CVE-2025-65074
No data.
OpenCVE Enrichment
No data.