CVE-2025-3002
nicheOS Command Injection in Digital China DCME-520 (CVE-2025-3002)
Digital China's DCME-520 contains an OS command injection flaw (CWE-77/CWE-78) in the script /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php, where the type_name parameter is passed to the operating system without adequate validation. The attack can be launched remotely over the network and requires no privileges or user interaction per the CVSS scoring, and other parameters in the affected script may also be vulnerable. An attacker who successfully exploits the flaw can inject and execute arbitrary operating system commands on the controller, potentially giving them control of the device and a foothold in the network it manages. Affected are DCME-520 deployments with firmware up to the 20250320 build; other DCME products are not confirmed in the available data. The exploit has been publicly disclosed and, with an EPSS of 20% (97th percentile), there is an elevated probability of exploitation in the next 30 days, though the flaw is not yet on the CISA KEV list and no public PoC code is catalogued.
What to do: Because no fixed version is published in the available data, contact Digital China or your reseller for a patched firmware for the DCME-520. In the meantime, restrict web-based management access to the controller (including the /usr/local/WWW/function/audit/newstatistics/ endpoint) to trusted management networks and disable internet-exposed management if possible. Check device logs for unexpected process executions or requests containing crafted type_name values to detect exploitation attempts.
| Digital China DCME-520 | up to 20250320 (firmware/builds through 2025-03-20) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.