CVE-2025-26055

MEDIUM

Infinxt iEdge 100 <2.1.32 - Command Injection

Title source: llm

Description

An OS Command Injection vulnerability exists in the Infinxt iEdge 100 2.1.32 Troubleshoot module, specifically in the tracertVal parameter of the Tracert function.

Exploits (1)

nomisec WRITEUP
by rohan-pt · poc
https://github.com/rohan-pt/CVE-2025-26055

Scores

CVSS v3 6.5
EPSS 0.0077
EPSS Percentile 73.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Published Apr 01, 2025
Tracked Since Feb 18, 2026