Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS command with root privileges.
Metrics
Affected Vendors & Products
References
History
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sony
Sony ncp-hg100 |
|
| Vendors & Products |
Sony
Sony ncp-hg100 |
Fri, 14 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Nov 2025 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS command with root privileges. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-11-14T05:15:56.229Z
Updated: 2025-11-14T15:21:59.245Z
Reserved: 2025-11-10T00:18:26.866Z
Link: CVE-2025-64444
Updated: 2025-11-14T15:21:51.155Z
Status : Awaiting Analysis
Published: 2025-11-14T06:15:42.877
Modified: 2025-11-14T16:42:03.187
Link: CVE-2025-64444
No data.