PT-2025-38520 · Undefined · Undefined

Published

2025-09-19

·

Updated

2025-09-19

·

CVE-2025-46418

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Westermo Network Technologies has identified a severe command injection vulnerability in its WeOS 5 operating system that could allow attackers to execute unauthorized commands remotely.
Key Points:
  • A CVSS v4 score of 8.7 indicates a high risk of exploitation.
  • Remote attackers with administrative access could execute unintended commands.
  • All versions of WeOS 5 from 5.24 and onwards are affected.
  • Mitigation involves limiting administrative access and utilizing secure remote access methods.
Westermo Network Technologies has reported a critical vulnerability in its WeOS 5 operating system, used primarily in industrial settings. The vulnerability, identified as CVE-2025-46418, is a result of improper neutralization of special elements utilized in operating system commands, commonly referred to as OS command injection. This issue allows an attacker, provided they have administrative permissions, to execute commands outside of their typical access rights, thereby posing a significant risk to system integrity and security.
This OS command injection vulnerability affects all versions of WeOS 5 starting from version 5.24, with a calculated CVSS v4 score of 8.7, indicating the severity of potential exploits. Organizations utilizing this operating system in critical infrastructure sectors—including commercial facilities, manufacturing, and energy—are urged to implement immediate defensive measures. Recommended actions from Westermo and CISA include restricting administrative access to trusted users and employing secure remote access methods such as VPNs, while also ensuring systems are not directly accessible from the internet.
Although no known public exploitation targeting this vulnerability has been reported thus far, the complexity of successful attacks remains high, emphasizing the need for proactive cybersecurity practices. CISA encourages users to adhere to best practices for managing administrative accounts and securing their networks against potential intrusions.
What steps are you taking to secure your systems against similar vulnerabilities?
Learn More: CISA
Want to stay updated on the latest cyber threats?

Related Identifiers

CVE-2025-46418

Affected Products

Undefined