OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exploited, an arbitrary OS command may be executed by the user who can log in to the device.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Apr 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OS command injection vulnerability exists in Deco BE65 Pro firmware versions prior to "Deco BE65 Pro(JP)_V1_1.1.2 Build 20250123". If this vulnerability is exploited, an arbitrary OS command may be executed by the user who can log in to the device. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-04-11T08:17:59.253Z
Updated: 2025-04-11T13:54:38.206Z
Reserved: 2025-04-04T05:54:42.718Z
Link: CVE-2025-32107
Updated: 2025-04-11T13:47:46.623Z
Status : Awaiting Analysis
Published: 2025-04-11T09:15:22.167
Modified: 2025-04-11T15:39:52.920
Link: CVE-2025-32107
No data.