First published: Thu May 15 2025(Updated: )
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA network attached hard disk 'HDL-T Series' firmware Ver.1.21 and earlier when 'Remote Link3 function' is enabled. If exploited, a remote unauthenticated attacker may execute an arbitrary OS command.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
I-O DATA HDL-T Series | <=1.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32002 has been classified with a high severity level due to the potential for remote code execution.
To mitigate CVE-2025-32002, update the firmware of your I-O DATA HDL-T Series device to version 1.22 or later.
CVE-2025-32002 affects users of the I-O DATA HDL-T Series firmware versions 1.21 and earlier.
CVE-2025-32002 is classified as an OS command injection vulnerability.
Yes, CVE-2025-32002 can be exploited by a remote unauthenticated attacker if the Remote Link3 function is enabled.