Shell Injection and Untrusted Search Path Vulnerabilities in Wazuh Agent and Manager
CVE-2025-15616
7.1HIGH
What is CVE-2025-15616?
Wazuh Agent and Manager contain multiple vulnerabilities related to shell injection and untrusted search paths, allowing malicious actors to execute arbitrary commands. Attackers can leverage these flaws through configuration files, SMTP server settings, and Kaspersky AR script parameters, potentially leading to remote code execution. It is crucial for users to update to versions 4.8.0 or later to mitigate this risk and enhance overall system security.
Affected Version(s)
wazuh-agent 2.1.0 < 4.8.0
wazuh-manager 2.1.0 < 4.8.0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Published by @vikman90.
Pedro Nicolas Gomez Palacios (Nicogp)
