PT-2025-19713 · Gefen · Gefen Webfwc

Troy Wilson

·

Published

2025-05-05

·

Updated

2025-05-05

·

CVE-2025-25504

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gefen WebFWC (In AV over IP products) versions 1.70, 1.85h, 1.86v
Description An issue in the /usr/local/bin/jncs.sh script allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.
Recommendations For version 1.70, update to a fixed version if available. For version 1.85h, update to a fixed version if available. For version 1.86v, update to a fixed version if available. As a temporary workaround, consider restricting access to the /usr/local/bin/jncs.sh script to minimize the risk of exploitation. Restrict access to TCP port 4444 to prevent unauthorized connections.

Exploit

Fix

Improper Authentication

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-25504

Affected Products

Gefen Webfwc