CVE-2025-46272: Planet Technology Network Products OS Command Injection
WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46272?
CVE-2025-46272 is classified as a critical vulnerability due to the potential for unauthenticated attackers to execute OS commands.
How do I fix CVE-2025-46272?
To fix CVE-2025-46272, update the affected Planet Technology products to their latest secure versions as specified in the vendor advisories.
Which products are affected by CVE-2025-46272?
CVE-2025-46272 affects the Planet Technology UNI-NMS-Lite versions 1.0b211018 and prior, NMS-500, NMS-1000V, WGS-804HPT-V2 versions 2.305b250121 and prior, and WGS-4215-8T2S versions 1.305b241115 and prior.
Can CVE-2025-46272 be exploited remotely?
Yes, CVE-2025-46272 can be exploited remotely by attackers without authentication.
What type of attack is associated with CVE-2025-46272?
CVE-2025-46272 is associated with a command injection attack, allowing execution of arbitrary OS commands.