CVE-2025-34033
5VTechnologies Blue Angel Software Suite OS Command Injection
CVSS v3
8.8
HIGH
EPSS Score
2.2 %
exploit probability
CISA KEV
No
known exploited
Exploitation
poc
SSVC status
Description
An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level ping command. An authenticated attacker can inject arbitrary commands by appending shell metacharacters to the ping_addr parameter in a crafted GET request to /cgi-bin/webctrl.cgi?action=pingtest_update. The command's output is reflected in the a
Technical details
- CVSS v3 Vector
- 3.1
- Published
- 2025-06-24
- Last Modified
- 2025-11-20
Frequently asked questions
What is CVE-2025-34033?
An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the ping_addr parameter in the webctrl.cgi script. The application fails to properly sanitize input before passing it to the system-level ping command. An authenticated attacker can inject arbitrary commands by appending shell metacharacters to the ping_addr parameter in a crafted GET request to /cgi-bin/webctrl.cgi?action=pingtest_update. The command's output is reflected in the a
Is CVE-2025-34033 actively exploited?
A proof-of-concept exploit exists for CVE-2025-34033, but active exploitation has not been confirmed at this time.
What is the CVSS score for CVE-2025-34033?
CVE-2025-34033 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string 3.1.
Is CVE-2025-34033 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2025 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).