CVE-2025-10364
Severity CVSS v4.0:
CRITICAL
Type:
CWE-77
Command Injection
Publication date:
12/09/2025
Last modified:
15/09/2025
Description
The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product<br />
features, setup network switching, and register license among other features. The application has been developed in PHP with the webEASY SDK, also named ‘ewb’ by Evertz.<br />
<br />
This web interface has two endpoints that are vulnerable to arbitrary command injection (CVE-2025-4009, CVE-2025-10364) and the authentication mechanism has a flaw leading to authentication bypass (CVE-2025-10365).<br />
<br />
CVE-2025-4009 covers the command injection in feature-transfer-import.php<br />
CVE-2025-10364 covers the command injection in feature-transfer-export.php<br />
<br />
Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices.<br />
<br />
This level of access could lead to serious business impact such as the interruption of media streaming, modification of media being streamed, alteration of closed captions being generated, among others.



