A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through the NTP settings. Successful exploitation may result in the device entering an infinite reboot loop, leading to a total or partial denial of connectivity for downstream systems that rely on its network services.
CVSS
No CVSS.
References
Configurations
No configuration.
History
02 Apr 2025, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-02 07:15
Updated : 2025-04-02 14:58
NVD link : CVE-2025-0415
Mitre link : CVE-2025-0415
CVE.ORG link : CVE-2025-0415
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')