← volver
CVE-2025-14213highCWE-20CWE-78

Cato's Socket WebUI is vulnerable to OS Command Injection

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 8.3epss 1.0%
probabilidad de explotación
1.0%top 39% de las CVE
explotación observada
noninguna fuente lo reporta
Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary operating system commands as the root user on the Socket’s internal system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:H
Productos afectados
Cato Networks · Socket