PT-2025-13672 · Unknown · Fast Lta Silent Brick Webui
Stefan Mettler
·
Published
2025-03-31
·
Updated
2025-04-02
·
CVE-2025-2071
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:N/RE:M/U:Amber |
Name of the Vulnerable Software and Affected Versions
FAST LTA Silent Brick WebUI versions prior to 2.63.04
Description
A critical OS Command Injection issue has been identified, allowing remote attackers to execute arbitrary operating system commands via specially crafted input. This issue arises due to improper handling of untrusted input, which is passed directly to system-level commands without adequate sanitization or validation. Successful exploitation could allow attackers to execute arbitrary commands on the affected system, potentially resulting in unauthorized access, data leakage, or full system compromise. The affected WebUI parameters are
hd and pi.Recommendations
For versions prior to 2.63.04, update to version 2.63.04 or later to resolve the issue. As a temporary workaround, consider restricting access to the
hd and pi parameters in the WebUI to minimize the risk of exploitation.Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fast Lta Silent Brick Webui