Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 1.7.4
affected
Default status
unaffected
0.0.0 (semver) before 1.7.4
affected
Default status
unaffected
0.0.0 (semver) before 1.7.4
affected
Default status
unaffected
0.0.0 (semver) before 1.7.4
affected
Description
An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting in a total loss of confidentiality, availability and integrity due to improper control of generation of code ('Code Injection').
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
0.0.0 (semver) before 1.7.4
0.0.0 (semver) before 1.7.4
0.0.0 (semver) before 1.7.4
0.0.0 (semver) before 1.7.4
Credits
Ryo Kato of Panasonic Holdings Corporation
References
phoenixcontact.csaf-tp.certvde.com/...2025/vde-2025-074.json