CVE-2025-25504
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.
Affected (3)
Products: Niceforyou: Gefen Webfwc
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.70v |
| Running on/with | Platform Versions |
|---|---|
Niceforyou Gefen Gf Avip Mc Firmware | Version a5.22 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.85h |
| Running on/with | Platform Versions |
|---|---|
Niceforyou Gefen Gf Avip Mc Firmware | Version a5.310 |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
References (1)
Timeline
No history available yet.