Description
An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can issue administrative CLI commands, altering the device configuration, and/or affecting its availability.
Problem types
CWE-863 Incorrect Authorization
Product status
Any version before 25.2.0
Any version before 25.2.0
Credits
This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.
References
security.nozominetworks.com/NN-2025:5-01