CVE-2025-0680
New Rock Technologies设备云RPC命令处理存在CWE-78漏洞,可能导致远程攻击者控制连接设备,厂商未回应CISA合作请求,建议用户联系客服获取更多信息。 2025-1-30 09:7:0 Author: claroty.com(查看原文) 阅读量:3 收藏

Critical Threat

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'):

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.

New Rock Technologies has not responded to requests to work with CISA to mitigate these vulnerabilities. Users of affected versions of New Rock Technologies Cloud Connected Devices are invited to contact New Rock Technologies customer support for additional information.


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-0680
如有侵权请联系:admin#unsafe.sh