First published: Thu Jan 16 2025(Updated: )
The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Netvision airPASS |
For v2.9.0.x, please update to version 2.9.0.241231 or later. For v3.0.0.x, please update to version 3.0.0.241231 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0457 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2025-0457, update the NetVision airPASS to the latest firmware version provided by the vendor.
CVE-2025-0457 affects users of the NetVision airPASS device with regular privileges.
CVE-2025-0457 is an OS Command Injection vulnerability that allows execution of arbitrary OS commands.
Yes, CVE-2025-0457 can be exploited remotely by attackers, requiring only regular privileges.