Skip to main content
HIGH

CVE-2025-34033

5VTechnologies Blue Angel Software Suite OS Command Injection

CVSS v3

8.8

HIGH

EPSS Score

2.2 %

exploit probability

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level ping command. An authenticated attacker can inject arbitrary commands by appending shell metacharacters to the ping_addr parameter in a crafted GET request to /cgi-bin/webctrl.cgi?action=pingtest_update. The command's output is reflected in the a

Technical details

CVSS v3 Vector
3.1
Published
2025-06-24
Last Modified
2025-11-20

Frequently asked questions

What is CVE-2025-34033?

An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level ping command. An authenticated attacker can inject arbitrary commands by appending shell metacharacters to the ping_addr parameter in a crafted GET request to /cgi-bin/webctrl.cgi?action=pingtest_update. The command's output is reflected in the a

Is CVE-2025-34033 actively exploited?

A proof-of-concept exploit exists for CVE-2025-34033, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2025-34033?

CVE-2025-34033 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string 3.1.

Is CVE-2025-34033 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key