CVE-2025-65074

WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server.A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path traversal in theshowerr script.

This issue was fixed in version 6.44.44
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CERT-PLCNA
---
---
CISA-ADPADP
---
---