CVE-2025-25504
PoC —CVSS 3.1
6.5 medium
EPSS
<1%p29
Published
()
Modified
Description
An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.
- Vendors
- niceforyou
- Products
- gefen webfwc
- Weakness
- CWE-77, CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.