CVE-2025-27078: Authenticated Remote Command Execution caused by Insecure Function Usage in System Binary
A vulnerability in a system binary of AOS-8 Instant and AOS-10 AP could allow an authenticated remote attacker to inject commands into the underlying operating system while using the CLI. Successful exploitation could lead to complete system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27078?
CVE-2025-27078 is considered a critical severity vulnerability due to its potential to allow complete system compromise.
How do I fix CVE-2025-27078?
To address CVE-2025-27078, it's essential to apply the latest security patches provided by the vendor AOS for AOS-8 Instant and AOS-10 AP.
What types of attacks can CVE-2025-27078 facilitate?
CVE-2025-27078 can facilitate command injection attacks, allowing an authenticated remote attacker to execute arbitrary commands on the operating system.
Who is affected by CVE-2025-27078?
CVE-2025-27078 affects users of AOS-8 Instant and AOS-10 AP systems that allow CLI access.
What are the potential consequences of exploiting CVE-2025-27078?
Exploitation of CVE-2025-27078 could lead to total system control and unauthorized access to sensitive information.