Description
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to execute arbitrary OS commands on the server using path traversal in the showerr script. This issue was fixed in version 6.44.44
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 6.44.44
Credits
Julia Zduńczyk
References
cert.pl/en/posts/2025/12/CVE-2025-65074
www.wavestore.com/products/video-management-software
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.