CVE-2025-1036None▾ SunlitCommand injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privileged network access for the configuration utility can execute arbitrary commands on the underlying …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.0%
Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privileged network access for the configuration utility can execute arbitrary commands on the underlying OS to obtain root SSH access to the TropOS 4th Gen device.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37912High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37897Critical· 9.8There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211)
CVE-2025-11490Medium· 6.3A vulnerability has been found in wonderwhy-er DesktopCommanderMCP up to 0.2.13
CVE-2025-11491Medium· 6.3A vulnerability was found in wonderwhy-er DesktopCommanderMCP up to 0.2.13
CVE-2025-11407Medium· 6.3A weakness has been identified in D-Link DI-7001 MINI 24.04.18B1
CVE-2025-1038NoneThe “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticated user with high privileges to inject commands into the command shell of the TropOS 4th Gen dev…