A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote attackers to execute arbitrary operating system commands via specially crafted input. This vulnerability arises due to improper handling of untrusted input, which is passed directly to system-level commands without adequate sanitization or validation. Successful exploitation could allow attackers to execute arbitrary commands on the affected system, potentially resulting in unauthorized access, data leakage, or full system compromise. Affected WebUI parameters are "hd" and "pi".
History

Mon, 31 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 08:45:00 +0000

Type Values Removed Values Added
Description A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote attackers to execute arbitrary operating system commands via specially crafted input. This vulnerability arises due to improper handling of untrusted input, which is passed directly to system-level commands without adequate sanitization or validation. Successful exploitation could allow attackers to execute arbitrary commands on the affected system, potentially resulting in unauthorized access, data leakage, or full system compromise. Affected WebUI parameters are "hd" and "pi".
Title OS Command Injection Vulnerability in FAST LTA Silent Brick WebUI
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:N/RE:M/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published: 2025-03-31T08:33:53.271Z

Updated: 2025-03-31T16:26:54.053Z

Reserved: 2025-03-06T18:18:48.091Z

Link: CVE-2025-2071

cve-icon Vulnrichment

Updated: 2025-03-31T16:26:43.125Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-31T09:15:14.807

Modified: 2025-04-01T20:26:30.593

Link: CVE-2025-2071

cve-icon Redhat

No data.