PT-2025-27825 · Igel · Igel Os
Rob Vinson
·
Published
2025-07-03
·
Updated
2025-07-04
·
CVE-2025-34082
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
IGEL OS versions prior to 11.04.270
Description:
A command injection issue exists due to improper input sanitization in the handling of specially crafted PROXYCMD commands on TCP ports 30022 and 5900. An unauthenticated attacker with network access to a vulnerable device can inject arbitrary commands, leading to remote code execution with elevated privileges.
Recommendations:
For IGEL OS versions prior to 11.04.270, update to version 11.04.270 or later to resolve the issue. As a temporary workaround, consider restricting access to TCP ports 30022 and 5900 to minimize the risk of exploitation.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Igel Os