CVE-2025-64444: OS Command Injection
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS command with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64444?
The severity of CVE-2025-64444 is critical, as it allows for OS command injection by authenticated users.
How do I fix CVE-2025-64444?
To fix CVE-2025-64444, update your NCP-HG100 to version 1.4.48.17 or later.
Who is affected by CVE-2025-64444?
Users of NCP-HG100 versions 1.4.48.16 and earlier are affected by CVE-2025-64444.
What kind of attack does CVE-2025-64444 facilitate?
CVE-2025-64444 facilitates OS command injection, allowing attackers to execute arbitrary commands.
What can be done to mitigate the risk of CVE-2025-64444?
To mitigate the risk of CVE-2025-64444, restrict access to the management interface and immediately apply the latest software updates.