PT-2026-29240 · Cato Networks · Cato Networks Socket
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2025-14213
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
Cato Networks Socket versions prior to 25
Description
An authenticated attacker with access to the Socket web interface (UI) can execute arbitrary operating system commands as the root user on the Socket’s internal system. The issue is a command injection. The affected component is the Socket web interface. The attacker needs to be authenticated to exploit this issue.
Recommendations
Update Cato Networks Socket to version 25 or later.
Fix
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cato Networks Socket