PT-2025-4147 · Ud-Lt2 · Ud-Lt2
Kaori Takashima
+2
·
Published
2025-01-22
·
Updated
2025-02-20
·
CVE-2025-20617
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UD-LT2 firmware versions 1.00.008 SE and earlier
Description
An issue exists due to the improper neutralization of special elements used in an OS command, allowing for the execution of arbitrary OS commands by an attacker with administrative access. This can be exploited by an attacker who can access the affected product with an administrative account.
Recommendations
For versions 1.00.008 SE and earlier, update to a version later than 1.00.008 SE to resolve the issue. As a temporary workaround, consider restricting administrative access to the affected product until a patch is available.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ud-Lt2