CVE-2025-41427

WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If a remote authenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be executed.
Configurations

No configuration.

History

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) WRC-X3000GS, WRC-X3000GSA y WRC-X3000GSN presentan una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('Inyección de comandos del sistema operativo') en la página Connection Diagnostics. Si un atacante remoto autenticado envía una solicitud especialmente manipulada al producto afectado, podría ejecutarse un comando arbitrario del sistema operativo.

24 Jun 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 05:15

Updated : 2025-06-26 18:58


NVD link : CVE-2025-41427

Mitre link : CVE-2025-41427

CVE.ORG link : CVE-2025-41427


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')