Back

MEDIUM

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames

Published Jun 23, 2025

Description

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mandiant
Published Jun 23, 2025
Updated Feb 26, 2026
Reserved Mar 10, 2025
CISA Vulnrichment
Updated Jun 24, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Mandiant
Published Jun 23, 2025
Updated Feb 26, 2026
Exploited since n/a
EUVD-2025-18898