PT-2025-30551 · Iotgen · Iotgen

Reid Wightman

·

Published

2025-07-23

·

Updated

2025-08-18

·

CVE-2025-41684

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions versions prior to 2.3
Description An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to improper sanitizing of user input in the Main Web Interface (endpoint tls iotgen setting).
Recommendations Update to version 2.3 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-41684

Affected Products

Iotgen