CVE-2025-26389: OS Command Injection
A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize the input parameters required for the exportDiagramPage endpoint. This could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26389?
CVE-2025-26389 is considered a high severity vulnerability due to its potential for remote code execution by unauthenticated attackers.
Which products are affected by CVE-2025-26389?
CVE-2025-26389 affects OZW672 and OZW772 versions prior to 8.0.
How do I fix CVE-2025-26389?
To fix CVE-2025-26389, upgrade the affected OZW672 and OZW772 devices to version 8.0 or higher.
What type of vulnerability is CVE-2025-26389?
CVE-2025-26389 is a code injection vulnerability due to improper input sanitization.
Can CVE-2025-26389 be exploited remotely?
Yes, CVE-2025-26389 can be exploited remotely by an unauthenticated attacker.