PT-2025-13672 · Unknown · Fast Lta Silent Brick Webui

Stefan Mettler

·

Published

2025-03-31

·

Updated

2025-04-02

·

CVE-2025-2071

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:N/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions FAST LTA Silent Brick WebUI versions prior to 2.63.04
Description A critical OS Command Injection issue has been identified, allowing remote attackers to execute arbitrary operating system commands via specially crafted input. This issue arises due to improper handling of untrusted input, which is passed directly to system-level commands without adequate sanitization or validation. Successful exploitation could allow attackers to execute arbitrary commands on the affected system, potentially resulting in unauthorized access, data leakage, or full system compromise. The affected WebUI parameters are hd and pi.
Recommendations For versions prior to 2.63.04, update to version 2.63.04 or later to resolve the issue. As a temporary workaround, consider restricting access to the hd and pi parameters in the WebUI to minimize the risk of exploitation.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-2071

Affected Products

Fast Lta Silent Brick Webui