← Back

CVE-2025-25504

nvd nist
Published: May 5, 2025Modified: Jul 5, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.

Affected (3)

1 product
Gefen Webfwc
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.70v
Running on/withPlatform Versions
Niceforyou
Gefen Gf Avip Mc Firmware
Version a5.22
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Niceforyou
Version 1.85h
Version 1.86v
Running on/withPlatform Versions
Niceforyou
Gefen Gf Avip Mc Firmware
Version a5.310

References (1)

Source: cve@mitre.org
ExploitThird Party Advisory

Timeline

No history available yet.