CVE-2025-46271
CRITICALPlanet Technology UNI-NMS-Lite < 1.0b211018 - Unauthenticated OS Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-46271. PoCs published by 1Altruist.
AI-analyzed exploit summary This PoC exploits a command injection vulnerability in UNI-NMS-Lite's login endpoint to achieve remote code execution. It downloads and executes a reverse shell via socat, leveraging a maliciously crafted username parameter.
Description
UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.
Exploits (1)
nomisec
WORKING POC
1 stars
by 1Altruist · poc
https://github.com/1Altruist/CVE-2025-46271-Reverse-Shell-PoC
This PoC exploits a command injection vulnerability in UNI-NMS-Lite's login endpoint to achieve remote code execution. It downloads and executes a reverse shell via socat, leveraging a maliciously crafted username parameter.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Planet Technology UNI-NMS-Lite Firmware Version 1.0b210426
No auth needed
Prerequisites:
Attacker-controlled HTTP server hosting socat binary · Network access to target's port 8888 (or custom port) · Socat listener on attacker's machine
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-06
Scores
CVSS v3
9.1
EPSS
0.0204
EPSS Percentile
78.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
Planet Technology/UNI-NMS-Lite
< 1.0b211018
Published
Apr 24, 2025
Tracked Since
Feb 18, 2026