CVE-2025-27083

Authenticated command injection vulnerabilities exist in the AOS-10 GW and AOS-8 Controller/Mobility Conductor web-based management interface. Successful exploitation of these vulnerabilities allows an Authenticated attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Configurations

No configuration.

History

09 Apr 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) Existen vulnerabilidades de inyección de comandos autenticados en la interfaz de gestión web de AOS-10 GW y AOS-8 Controller/Mobility Conductor. La explotación exitosa de estas vulnerabilidades permite a un atacante autenticado ejecutar comandos arbitrarios como usuario privilegiado en el sistema operativo subyacente.
CWE CWE-77

08 Apr 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 17:15

Updated : 2025-04-09 18:15


NVD link : CVE-2025-27083

Mitre link : CVE-2025-27083

CVE.ORG link : CVE-2025-27083


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')