CVE-2025-50475
Last modified
CVE-2025-50475 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitrary commands as root via crafted input to the hostname parameter in network configuration requests. This vulnerability stems from improper neutralization of special elements used in an OS command within the network configuration handler, enabling remote code execution with the highest privileges.. EPSS estimates a 7.93% chance of exploitation in the next 30 days.
Description
An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitrary commands as root via crafted input to the hostname parameter in network configuration requests. This vulnerability stems from improper neutralization of special elements used in an OS command within the network configuration handler, enabling remote code execution with the highest privileges.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-50475?
How severe is CVE-2025-50475?
How do I fix CVE-2025-50475?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-50465OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An atta…8.8
- CVE-2025-50466OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An atta…6.5
- CVE-2025-50467OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An atta…6.5
- CVE-2025-50468OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An atta…6.5
- CVE-2025-5047A maliciously crafted DGN file, when parsed through Autodesk…7.8
- CVE-2025-50472The modelscope/ms-swift library thru 2.6.1 is vulnerable to …9.8
- CVE-2025-50477A URL redirection in lbry-desktop v0.53.9 allows attackers t…5.4
- CVE-2025-5048A maliciously crafted DGN file, when linked or imported into…7.8
- CVE-2025-50481A cross-site scripting (XSS) vulnerability in the component …4.8
- CVE-2025-50484Improper session invalidation in the component /crm/change-p…7.1
- CVE-2025-50485Improper session invalidation in the component /crm/change-p…7.1
- CVE-2025-50486Improper session invalidation in the component /carrental/up…7.1
Are you affected by CVE-2025-50475?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
