We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).
Reserved 2025-04-16 | Published 2025-07-23 | Updated 2025-07-23 | Assigner CERTVDECWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Reid Wightman of Dragos Inc.
certvde.com/de/advisories/VDE-2025-052
Support options