An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.
History

Mon, 05 May 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
CWE-77
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 May 2025 15:30:00 +0000

Type Values Removed Values Added
Description An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-05-05T00:00:00.000Z

Updated: 2025-05-05T17:38:43.878Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-25504

cve-icon Vulnrichment

Updated: 2025-05-05T17:38:37.192Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-05T16:15:50.640

Modified: 2025-05-05T20:54:19.760

Link: CVE-2025-25504

cve-icon Redhat

No data.