CVE-2025-24347
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 30, 2025
Updated: May 2, 2025
CWE ID 1286
Summary
CVE-2025-24347 is a vulnerability affecting the "Network Interfaces" functionality of the ctrlX OS web application. This issue permits a remote, low-privileged attacker to manipulate the network configuration file via a specially crafted HTTP request. Successful exploitation could result in unauthorized network configuration changes, potentially leading to denial-of-service conditions or data exfiltration. It is crucial for organizations using ctrlX OS to apply the necessary patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.