CVE-2025-15616: Wazuh Agent and Manager OS Command Injection and Untrusted Search Path
Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags, and Kaspersky AR script parameters. Attackers can exploit these vulnerabilities by injecting malicious commands through configuration files, SMTP server settings, and custom flags to achieve remote code execution on affected systems.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wazuhto a version that resolves this vulnerability.Fixed in 4.8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15616?
CVE-2025-15616 is considered a high severity vulnerability due to its potential to allow arbitrary command execution.
How do I fix CVE-2025-15616?
To fix CVE-2025-15616, update Wazuh Agent and Wazuh Manager to version 4.8.0 or later.
What types of flaws are associated with CVE-2025-15616?
CVE-2025-15616 is associated with shell injection and path traversal flaws.
Which versions of Wazuh are affected by CVE-2025-15616?
Wazuh Agent and Wazuh Manager versions from 2.1.0 to before 4.8.0 are affected by CVE-2025-15616.
What can attackers do exploiting CVE-2025-15616?
Exploiting CVE-2025-15616 allows attackers to execute arbitrary commands through various components of the affected software.