CVE-2025-3499

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
09/07/2025
Last modified:
10/07/2025

Description

The device has two web servers that expose unauthenticated REST APIs on the management network (TCP<br /> ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary<br /> commands that are executed with administrative permissions by the underlying operating system.

References to Advisories, Solutions, and Tools