CVE-2025-41684HIGH 8.8EPSS p47.0%
CVE-2025-41684CVE-2025-41684
Description
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting).
Scoring
| CVSS 3.1 | 8.8 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.67% probability of exploitation · percentile 47.0% · 2026-06-18T12:00:27Z |
| Published | 2025-07-23 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-78 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.