August 3, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-2172NVD

Vulnerability Summary

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames
Severity Level
MEDIUM(6.6)
Published Date
Jun 23, 2025
Last Modified
Jun 23, 2025
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software constructs all or part of an OS command using externally-influenced input, but does not properly neutralize special elements.
CVSS v4.0 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredHigh
User InteractionNone