IM
IronMonkey Threat Research

CVE-2025-50121 CRITICAL

Published: 2025-07-11 | Last Modified: 2026-04-15 | Status: Deferred

Description

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. HTTP is disabled by default.

Additional Descriptions (1)

Existe una vulnerabilidad CWE-78: Neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('Inyección de comandos del sistema operativo') que podría causar la ejecución remota de código no autenticado al crear una carpeta maliciosa a través de la interfaz web HTTP cuando está habilitada. HTTP está deshabilitado de forma predeterminada.

CVSS Metrics

Base Score: 9.5 (CRITICAL)

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityLOW
Attack RequirementsPRESENT
Privileges RequiredNONE
User InteractionNONE
Vulnerability ConfidentialityHIGH
Vulnerability IntegrityHIGH
Vulnerability AvailabilityHIGH
Subsequent ConfidentialityHIGH
Subsequent IntegrityLOW
Subsequent AvailabilityHIGH

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-78
Notification
Message here