A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.
References
History

Mon, 14 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 18:45:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-04-01T00:00:00.000Z

Updated: 2025-04-14T17:41:23.657Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-26056

cve-icon Vulnrichment

Updated: 2025-04-14T17:41:14.549Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-01T19:15:44.427

Modified: 2025-04-14T18:15:28.560

Link: CVE-2025-26056

cve-icon Redhat

No data.