← back
CVE-2025-0415

Command Injection in NTP Setting

CVSS 9.2 CRITICALEPSS 0.5%CWE-78
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.2EPSS 0.5%KEV nãoPoC Patch referenciado
Lifecycle
02 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through the NTP settings. Successful exploitation may result in the device entering an infinite reboot loop, leading to a total or partial denial of connectivity for downstream systems that rely on its network services.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →