CVE-2025-64126

An OS command injection vulnerability exists due to improper input 
validation. The application accepts a parameter directly from user input
 without verifying it is a valid IP address or filtering potentially 
malicious characters. This could allow an unauthenticated attacker to 
inject arbitrary commands.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
icscertCNA
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA-ADPADP
---
---