CVE-2025-53695

OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.
CVSS

No CVSS.

Configurations

No configuration.

History

29 Jul 2025, 14:14

Type Values Removed Values Added
Summary
  • (es) La inyección de comandos del sistema operativo en la aplicación web de los productos iSTAR Ultra permite que un atacante autenticado obtenga acceso aún más privilegiado (usuario "root") al firmware del dispositivo.

28 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-28 14:15

Updated : 2025-07-29 14:14


NVD link : CVE-2025-53695

Mitre link : CVE-2025-53695

CVE.ORG link : CVE-2025-53695


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')