PT-2026-29240 · Cato Networks · Cato Networks Socket

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2025-14213

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Cato Networks Socket versions prior to 25
Description An authenticated attacker with access to the Socket web interface (UI) can execute arbitrary operating system commands as the root user on the Socket’s internal system. The issue is a command injection. The affected component is the Socket web interface. The attacker needs to be authenticated to exploit this issue.
Recommendations Update Cato Networks Socket to version 25 or later.

Fix

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-14213

Affected Products

Cato Networks Socket