CVE-2025-46418
nicheOS Command Injection in Westermo WeOS 5.24+ via Media Definition
Westermo WeOS, the operating system running on the vendor's industrial Ethernet switches and routers, is vulnerable to OS command injection (CWE-78) through a media definition, a flaw present in WeOS 5 builds from version 5.24 onward. Triggering it requires an authenticated, highly privileged user to interact with the affected media definition parameter, and the network-adjacent complexity of the attack is high per the CVSS scoring. Because the scope changes, an attacker can break out of the WeOS management context and execute operating-system commands on the device itself, gaining high-impact control over confidentiality, integrity, and availability of the unit. Operators running WeOS 5.24 or later on Westermo industrial networking hardware are in scope. The flaw is not yet listed in CISA KEV, has no known public proof-of-concept, and EPSS currently assigns only a 0.7% probability of exploitation within 30 days.
What to do: Inventory Westermo devices and check WeOS versions, flagging any unit on 5.24 or later, then apply the patched WeOS 5 release per Westermo's advisory once published (no fixed version is given in the current data). Until patching, restrict management access to the WeOS CLI/web interface to trusted administrators and keep management interfaces off exposed or shared networks. Since exploitation requires high-privilege authenticated access, review which accounts can modify media definitions and monitor Westermo's channel for exploit updates given the CVSS scope-change impact.
| Westermo WeOS 5 (industrial switch/router OS) | WeOS 5.x versions 5.24 and later; fixed version not specified in the source data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.