An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://gefen.com | Product |
https://www.troy-wilson.com/cve-2025-25504.html | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
History
17 Jun 2025, 14:13
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:niceforyou:gefen_webfwc:1.70v:*:*:*:*:*:*:* cpe:2.3:a:niceforyou:gefen_webfwc:1.86v:*:*:*:*:*:*:* cpe:2.3:a:niceforyou:gefen_webfwc:1.85h:*:*:*:*:*:*:* cpe:2.3:o:niceforyou:gefen_gf-avip-mc_firmware:a5.22:*:*:*:*:*:*:* cpe:2.3:o:niceforyou:gefen_gf-avip-mc_firmware:a5.310:*:*:*:*:*:*:* |
|
References | () http://gefen.com - Product | |
References | () https://www.troy-wilson.com/cve-2025-25504.html - Exploit, Third Party Advisory | |
First Time |
Niceforyou
Niceforyou gefen Gf-avip-mc Firmware Niceforyou gefen Webfwc |
05 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-05 16:15
Updated : 2025-06-17 14:13
NVD link : CVE-2025-25504
Mitre link : CVE-2025-25504
JSON object : View
Products Affected
niceforyou
- gefen_gf-avip-mc_firmware
- gefen_webfwc
CWE
No CWE.