A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://certvde.com/de/advisories/VDE-2025-058 |
![]() ![]() |
History
Tue, 22 Jul 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Helmholz
Helmholz rex 100 Mb Connect Line Mb Connect Line mbnet.mini |
|
Vendors & Products |
Helmholz
Helmholz rex 100 Mb Connect Line Mb Connect Line mbnet.mini |
Mon, 21 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 21 Jul 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. | |
Title | Remote Command Injection via GET in Cloud Server Communication Script Due to Improper Input Neutralization | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: CERTVDE
Published: 2025-07-21T09:29:57.024Z
Updated: 2025-07-21T20:36:45.460Z
Reserved: 2025-04-16T11:17:48.308Z
Link: CVE-2025-41675

Updated: 2025-07-21T20:35:41.686Z

Status : Awaiting Analysis
Published: 2025-07-21T10:15:24.530
Modified: 2025-07-22T13:06:07.260
Link: CVE-2025-41675

No data.