CVE-2025-10265

Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
Configurations

No configuration.

History

15 Sep 2025, 04:15

Type Values Removed Values Added
Summary (en) Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device. (en) Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.8

12 Sep 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-12 11:15

Updated : 2025-09-15 15:21


NVD link : CVE-2025-10265

Mitre link : CVE-2025-10265

CVE.ORG link : CVE-2025-10265


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')