CVE-2025-41385

An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS command may be executed by a logged-in administrative user.
References
Link Resource
https://jvn.jp/en/jp/JVN51394666/ Third Party Advisory
https://www.uchida.co.jp/wivia/support02.html Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:uchida:wivia_5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:uchida:wivia_5:-:*:*:*:*:*:*:*

History

04 Jun 2025, 19:58

Type Values Removed Values Added
First Time Uchida
Uchida wivia 5 Firmware
Uchida wivia 5
CPE cpe:2.3:h:uchida:wivia_5:-:*:*:*:*:*:*:*
cpe:2.3:o:uchida:wivia_5_firmware:*:*:*:*:*:*:*:*
References () https://jvn.jp/en/jp/JVN51394666/ - () https://jvn.jp/en/jp/JVN51394666/ - Third Party Advisory
References () https://www.uchida.co.jp/wivia/support02.html - () https://www.uchida.co.jp/wivia/support02.html - Vendor Advisory
CVSS v2 : unknown
v3 : 6.7
v2 : unknown
v3 : 7.2

30 May 2025, 16:31

Type Values Removed Values Added
Summary
  • (es) Existe un problema de inyección de comandos del sistema operativo en todas las versiones de Wivia 5. Si se explota esta vulnerabilidad, un usuario administrador con sesión iniciada podría ejecutar un comando arbitrario del sistema operativo.

30 May 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-30 07:15

Updated : 2025-06-04 19:58


NVD link : CVE-2025-41385

Mitre link : CVE-2025-41385

CVE.ORG link : CVE-2025-41385


JSON object : View

Products Affected

uchida

  • wivia_5_firmware
  • wivia_5
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')