CVE-2025-3499
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
09/07/2025
Last modified:
10/07/2025
Description
The device has two web servers that expose unauthenticated REST APIs on the management network (TCP<br />
ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary<br />
commands that are executed with administrative permissions by the underlying operating system.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL



