Arbitrary Command Execution Vulnerability in Evertz High Bandwidth Ethernet Switching Fabric
CVE-2025-10365

9.3CRITICAL

Key Information:

Vendor

Evertz

Vendor
CVE Published:
12 September 2025

What is CVE-2025-10365?

The Evertz SDVN 3080ipx-10G, a High Bandwidth Ethernet Switching Fabric designed for video applications, contains vulnerabilities within its web management interface exposed on port 80. This interface allows administrators to manage various product features and configurations. However, flaws in the authentication mechanism may permit remote unauthenticated attackers to execute arbitrary commands with elevated privileges on the device. Such vulnerabilities can lead to significant operational disruptions, including the manipulation of media streams and modifications to critical closed captioning processes.

Affected Version(s)

3080ipx-10G 0

5782XPS-APP-4E 0

7890IXG 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Q. Kaiser from ONEKEY Research Labs
.