CVE-2025-65075
16.12.2025, 13:15
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete files, with the permissions ofdvr user, on the server using path traversal in thealog script. This issue was fixed in version 6.44.44
| Vendor | Product | Version |
|---|---|---|
| wavestore | video_management_software_server | 𝑥 ≤ 6.42.4 |
𝑥
= Vulnerable software versions