PT-2025-51559 · Unknown+1 · Wavestore Server+1

Julia Zduńczyk

·

Published

2025-12-16

·

Updated

2025-12-16

·

CVE-2025-65075

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WaveView versions prior to 6.44.44
Description A malicious attacker with high-privileges can read or delete files, with the permissions of the dvr user, on the server using path traversal in the alog script. The issue affects systems where users execute a restricted set of predefined commands and scripts on a connected WaveStore Server.
Recommendations Update to version 6.44.44 or later.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-65075

Affected Products

Wavestore Server
Waveview