CVE-2025-50121

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. HTTP is disabled by default.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Jul 2025, 13:14

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad CWE-78: Neutralización incorrecta de elementos especiales utilizados en un comando del sistema operativo ('Inyección de comandos del sistema operativo') que podría causar la ejecución remota de código no autenticado al crear una carpeta maliciosa a través de la interfaz web HTTP cuando está habilitada. HTTP está deshabilitado de forma predeterminada.

14 Jul 2025, 00:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 10.0
v2 : unknown
v3 : unknown
Summary (en) CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. HTTP is disabled by default. (en) A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause unauthenticated remote code execution when a malicious folder is created over the web interface HTTP when enabled. HTTP is disabled by default.

11 Jul 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-11 10:15

Updated : 2025-07-15 13:14


NVD link : CVE-2025-50121

Mitre link : CVE-2025-50121

CVE.ORG link : CVE-2025-50121


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')