CVE-2025-24306

CVSS 3.0 Score 7.2 of 10 (high)

Details

Published Mar 18, 2025
CWE ID 78

Summary

CVE-2025-24306 is a critical OS Command Injection vulnerability affecting +F FS010M versions before V2.0.0_1101. This issue allows a remote, authenticated attacker with administrative privileges to execute arbitrary OS commands, posing a significant security risk. The vulnerability arises due to a failure to properly neutralize special elements in OS commands. This issue could result in unauthorized system access, data theft, or system damage. It is strongly recommended that users upgrade to the latest version of +F FS010M as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share