CVE-2025-11546: OS Command Injection
CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11546?
CVE-2025-11546 is classified as a medium-severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-11546?
To fix CVE-2025-11546, upgrade NEC UNIVERGE IX to the latest version recommended by NEC Corporation.
What versions of NEC UNIVERGE IX are affected by CVE-2025-11546?
CVE-2025-11546 affects NEC UNIVERGE IX versions from 9.5 to 10.7, and 10.8.21 to 10.8.36, 10.9.11 to 10.9.24, and 10.10.21 to 10.10.31.
Can CVE-2025-11546 lead to data breaches?
Yes, CVE-2025-11546 can allow attackers to execute scripts in users' browsers, potentially leading to data breaches.
Is there a workaround for CVE-2025-11546?
While there is no official workaround for CVE-2025-11546, users are advised to restrict access to the vulnerable applications until they can upgrade.