A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.
History

Tue, 22 Jul 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Helmholz
Helmholz rex 100
Mb Connect Line
Mb Connect Line mbnet.mini
Vendors & Products Helmholz
Helmholz rex 100
Mb Connect Line
Mb Connect Line mbnet.mini

Mon, 21 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Jul 2025 09:45:00 +0000

Type Values Removed Values Added
Description A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.
Title Remote Command Injection via GET in Cloud Server Communication Script Due to Improper Input Neutralization
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published: 2025-07-21T09:29:57.024Z

Updated: 2025-07-21T20:36:45.460Z

Reserved: 2025-04-16T11:17:48.308Z

Link: CVE-2025-41675

cve-icon Vulnrichment

Updated: 2025-07-21T20:35:41.686Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-21T10:15:24.530

Modified: 2025-07-22T13:06:07.260

Link: CVE-2025-41675

cve-icon Redhat

No data.