PT-2025-26597 · Aviatrix · Aviatrix Controller

Louis Dion-Marcil

·

Published

2025-06-23

·

Updated

2025-07-31

·

CVE-2025-2172

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Aviatrix Controller versions prior to 7.1.4208 Aviatrix Controller versions prior to 7.2.5090 Aviatrix Controller versions prior to 8.0.0
Description: The issue is related to the failure of the Aviatrix Controller to sanitize user input before passing it to command line utilities. This allows command injection via special characters in filenames.
Recommendations: For versions prior to 7.1.4208, update to version 7.1.4208 or later. For versions prior to 7.2.5090, update to version 7.2.5090 or later. For versions prior to 8.0.0, update to version 8.0.0 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-2172

Affected Products

Aviatrix Controller