A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpensuse Backports Sle
APPOpensuse15.0Opensuse Leap
OSOpensuse15.115.2Ui Edgeswitch Firmware
APPUi< 1.9.0Ui Ep 16 Xg
HWUiall versionsUi Ep S16
HWUiall versionsUi Es 12f
HWUiall versionsUi Es 16 150w
HWUiall versionsUi Es 24 250w
HWUiall versionsUi Es 24 500w
HWUiall versionsUi Es 24 Lite
HWUiall versionsUi Es 48 500w
HWUiall versionsUi Es 48 750w
HWUiall versionsUi Es 48 Lite
HWUiall versionsUi Es 8 150w
HWUiall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
LPECommand Injection
References
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2020-16846CRITICAL9.8⚠ KEVPL ✓same product
SaltStack Salt API — shell injection przez klienta SSH (RCE)
CVE-2020-15999CRITICAL9.6⚠ KEVPL ✓same product
Heap buffer overflow w FreeType w Google Chrome — aktywnie exploitowany
CVE-2020-12641CRITICAL9.8⚠ KEVPL ✓same product
Command injection w Roundcube Webmail — RCE przez konfigurację ImageMagick
CVE-2020-11651CRITICAL9.8⚠ KEVPL ✓same product
SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE