CVE-2025-24351: OS Command Injection
A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to execute arbitrary OS commands in the context of user “root” via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24351?
CVE-2025-24351 has been rated as critical due to its potential to allow remote command execution as the root user.
How do I fix CVE-2025-24351?
To mitigate CVE-2025-24351, update to the latest version of Bosch ctrlX OS that addresses this vulnerability.
Who is affected by CVE-2025-24351?
CVE-2025-24351 affects users of Bosch ctrlX OS with the remote logging feature enabled.
What types of attacks can be performed using CVE-2025-24351?
CVE-2025-24351 allows an authenticated low-privileged attacker to execute arbitrary OS commands on affected systems.
Is authentication required to exploit CVE-2025-24351?
Yes, CVE-2025-24351 requires the attacker to be authenticated as a low-privileged user to exploit this vulnerability.