CVE-2025-26856
CVSS 3.0 Score 7.2 of 10 (high)
Details
Published Feb 20, 2025
CWE ID 78
Summary
CVE-2025-26856 is a newly identified OS Command Injection vulnerability affecting UD-LT2 firmware versions 1.00.008_SE and prior. If an attacker gains administrative access, they can manipulate specific screen operation requests, leading to the execution of arbitrary OS commands. This vulnerability was discovered during investigations of a different screen operation than CVE-2025-20617.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share