An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who is logging in to the device.
History

Mon, 30 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 05:45:00 +0000

Type Values Removed Values Added
Description An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who is logging in to the device.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2025-06-27T05:23:27.330Z

Updated: 2025-06-30T18:47:15.964Z

Reserved: 2025-06-24T23:58:17.896Z

Link: CVE-2025-36529

cve-icon Vulnrichment

Updated: 2025-06-30T18:47:08.221Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-27T06:15:24.587

Modified: 2025-06-30T18:38:48.477

Link: CVE-2025-36529

cve-icon Redhat

No data.