216.73.216.233

CVE-2025-64126

· Published 26/11/2025 18:15 · Modified 01/12/2025 15:39

Labels: CVE-2025-64126 2025-11-26CVE-2025-64126CWE-78[email protected]

Essential information

Published
26/11/2025 18:15
Modified
01/12/2025 15:39
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a valid IP address or filtering potentially malicious characters. This could allow an unauthenticated attacker to inject arbitrary commands.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References