The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExtremenetworks Aerohive Netconfig
HWExtremenetworks10.0r8a< 10.0r8a
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2024-38292CRITICAL9.8PL ✓same vendor
Path traversal w Extreme Networks XIQ-SE umożliwiający privilege escalation
CVE-2023-43119CRITICAL9.8PL ✓same vendor
Extreme Networks EXOS — privilege escalation przez Redis i Telnet
CVE-2023-35803CRITICAL9.8PL ✓same vendor
Buffer overflow w IQ Engine na urządzeniach Extreme Networks AP
CVE-2023-35802CRITICAL9.8PL ✓same vendor
Buffer overflow w protokole CAPWAP urządzeń Extreme Networks AP — RCE
CVE-2025-11192HIGH8.4same vendor
A vulnerability in Extreme Networks’ Fabric Engine (VOSS) before 9.3 was discovered. When SD-WAN AutoSense is ...