CVE-2025-64128

EUVD-2025-199740
An OS command injection vulnerability exists due to incomplete 
validation of user-supplied input. Validation fails to enforce 
sufficient formatting rules, which could permit attackers to append 
arbitrary data. This could allow an unauthenticated attacker to inject 
arbitrary commands.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
icscertCNA
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H