Command Injection Vulnerability in Evertz SDVN 3080ipx-10G Web Management Interface
CVE-2025-10364

9.3CRITICAL

Key Information:

Vendor

Evertz

Vendor
CVE Published:
12 September 2025

What is CVE-2025-10364?

The Evertz SDVN 3080ipx-10G device, designed for high bandwidth Ethernet switching in video applications, features a web management interface that is susceptible to command injection vulnerabilities. This interface operates on port 80 and allows administrators to manage device features, configure network switching, and handle licensing. However, flaws in its authentication mechanism can lead to unauthorized access, enabling remote attackers to execute arbitrary commands with elevated privileges. Such exploitation could severely impact media streaming operations, including disruptions in content delivery and modifications to streamed media.

Affected Version(s)

3080ipx-10G 0

5782XPS-APP-4E 0

7890IXG 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Q. Kaiser from ONEKEY Research Labs
.