CVE-2025-20617

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If an attacker logs in to the affected product with an administrative account and manipulates requests for a certain screen operation, an arbitrary OS command may be executed. This vulnerability was reported on a different screen operation from CVE-2025-26856.
Configurations

No configuration.

History

20 Feb 2025, 06:15

Type Values Removed Values Added
Summary
  • (es) Existe un problema de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('Inyección de comando del sistema operativo') en el firmware UD-LT2 Ver.1.00.008_SE y anteriores. Si se explota esta vulnerabilidad, un atacante que pueda acceder al producto afectado con una cuenta administrativa puede ejecutar un comando arbitrario del sistema operativo.
Summary (en) Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can access the affected product with an administrative account. (en) Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If an attacker logs in to the affected product with an administrative account and manipulates requests for a certain screen operation, an arbitrary OS command may be executed. This vulnerability was reported on a different screen operation from CVE-2025-26856.

22 Jan 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-22 06:15

Updated : 2025-02-20 06:15


NVD link : CVE-2025-20617

Mitre link : CVE-2025-20617

CVE.ORG link : CVE-2025-20617


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')