ZeroHour

CVE-2025-25504

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p29
Published
()
Modified
Description

An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.

Vendors
niceforyou
Products
gefen webfwc
Weakness
CWE-77, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.