CVE-2025-20016

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 78

Summary

CVE-2025-20016 is a critical command injection vulnerability affecting the STEALTHONE D220, D340, and D440 network storage servers provided by Y'S corporation. This issue allows an administrative user, who gains access to the web management page, to execute arbitrary OS commands, posing a significant security risk. Attackers could exploit this vulnerability to take control of the server, install malware, or steal sensitive data. The vulnerability has the potential to impact organizations that have deployed these specific storage servers, and immediate action is recommended to mitigate the risk, such as applying the available patch or configuring access controls to prevent unauthorized access to the web management page.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share