CVE-2025-26056

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 14, 2025
CWE ID 77

Summary

CVE-2025-26056 is a command injection vulnerability affecting the Infinxt iEdge 1.0 2.1.32 Troubleshoot module's "MTR" functionality. This issue arises due to insufficient validation of user-supplied input in the mtrIp parameter. Malicious actors can exploit this weakness to execute arbitrary operating system commands on the underlying system, holding the same privileges as the web application process. This vulnerability poses a significant risk if left unpatched, potentially leading to unauthorized system access and data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share