CVE-2025-41674: Remote Command Injection in diagnostic Action Due to Improper Input Neutralization
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41674?
CVE-2025-41674 has been assigned a high severity rating due to its potential for remote arbitrary command execution.
How do I fix CVE-2025-41674?
To mitigate CVE-2025-41674, it is recommended to upgrade to the latest version of the Mbnet.mini firmware above 2.3.3.
Who is affected by CVE-2025-41674?
CVE-2025-41674 affects users of Mbconnectline's Mbnet.mini firmware version 2.3.3 and below.
What types of attacks are possible with CVE-2025-41674?
CVE-2025-41674 allows attackers to execute arbitrary system commands on the affected device through specially crafted POST requests.
Is there a known exploit for CVE-2025-41674?
Yes, there are reports indicating that CVE-2025-41674 can be exploited by attackers to gain elevated privileges remotely.