CVE-2025-31644

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Configurations

No configuration.

History

08 May 2025, 14:39

Type Values Removed Values Added
Summary
  • (es) Al ejecutarse en modo Appliance, existe una vulnerabilidad de inyección de comandos en un comando no revelado de iControl REST y BIG-IP TMOS Shell (tmsh), que podría permitir que un atacante autenticado con privilegios de administrador ejecute comandos arbitrarios del sistema. Una explotación exitosa puede permitir al atacante traspasar una barrera de seguridad. Nota: Las versiones de software que han alcanzado el fin del soporte técnico (EoTS) no se evalúan.

07 May 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-07 22:15

Updated : 2025-05-08 14:39


NVD link : CVE-2025-31644

Mitre link : CVE-2025-31644

CVE.ORG link : CVE-2025-31644


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')