CVE-2025-26056

MEDIUM

Infinxt iEdge 100 2.1.32 - Command Injection

Title source: llm

Description

A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on the underlying system with the same privileges as the web application process.

Exploits (1)

nomisec WRITEUP
by rohan-pt · poc
https://github.com/rohan-pt/CVE-2025-26056

Scores

CVSS v3 5.4
EPSS 0.0061
EPSS Percentile 69.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Published Apr 01, 2025
Tracked Since Feb 18, 2026