CVE-2025-41675
HIGHCVSS 7.2/10EPSS 0.59%
Last modified
CVE-2025-41675 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mbconnectline | Mbnet.Mini Firmware | < 2.3.3 |
References
- https://certvde.com/de/advisories/VDE-2025-058Vendor Advisory
- http://seclists.org/fulldisclosure/2025/Jul/38Mailing List
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-41675?
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command.
How severe is CVE-2025-41675?
CVE-2025-41675 has a CVSS score of 7.2/10 (HIGH severity). The EPSS model estimates a 0.59% probability of exploitation in the next 30 days.
How do I fix CVE-2025-41675?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-41668A low privileged remote attacker with file access can replac…8.8
- CVE-2025-41669The Web-based Management allows a remote low privileged Engi…8.8
- CVE-2025-41670A local user with low privileges may be able to influence th…8.7
- CVE-2025-41672A remote unauthenticated attacker may use default certificat…10
- CVE-2025-41673A high privileged remote attacker can execute arbitrary syst…7.2
- CVE-2025-41674A high privileged remote attacker can execute arbitrary syst…7.2
- CVE-2025-41676A high privileged remote attacker can exhaust critical syste…4.9
- CVE-2025-41677A high privileged remote attacker can exhaust critical syste…4.9
- CVE-2025-41678A high privileged remote attacker can alter the configuratio…7.2
- CVE-2025-41679An unauthenticated remote attacker could exploit a buffer ov…7.5
- CVE-2025-4168The Subpage List plugin for WordPress is vulnerable to Store…6.4
- CVE-2025-41681A high privileged remote attacker can gain persistent XSS vi…4.8
Are you affected by CVE-2025-41675?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
