PT-2025-14379 · Infinxt · Infinxt Iedge 100
Published
2025-04-01
·
Updated
2025-04-05
·
CVE-2025-26056
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Infinxt iEdge 100 version 2.1.32
Description
A command injection issue exists in the Troubleshoot module's "MTR" functionality due to improper validation of user-supplied input in the
mtrIp parameter. This allows an attacker to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.Recommendations
For Infinxt iEdge 100 version 2.1.32, consider disabling the "MTR" functionality in the Troubleshoot module until a patch is available to prevent exploitation of the command injection flaw. Restrict access to the
mtrIp parameter to minimize the risk of arbitrary command execution.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infinxt Iedge 100