OS Command Injection in FAST LTA Silent Brick WebUI
CVE-2025-2071

10CRITICAL

Key Information:

Vendor

Fast Lta

Vendor
CVE Published:
31 March 2025

What is CVE-2025-2071?

CVE-2025-2071 is a critical vulnerability found in the FAST LTA Silent Brick WebUI, a system designed for managing data storage solutions. This vulnerability allows remote attackers to perform OS command injection by inputting specially crafted data, which can lead to arbitrary operating system command execution. If exploited, this flaw can severely undermine an organization's security by facilitating unauthorized access to sensitive data and system resources, ultimately jeopardizing the integrity and availability of the affected systems.

Technical Details

CVE-2025-2071 occurs due to insufficient validation and sanitization of user input within the Silent Brick WebUI. The compromised parameters "hd" and "pi" are susceptible to injection attacks, where attackers can manipulate inputs to execute arbitrary commands on the server. This vulnerability demonstrates a worrying lapse in security best practices, enabling potential exploitation without requiring advanced skills or resources.

Potential Impact of CVE-2025-2071

  1. Unauthorized Access: Attackers could gain unauthorized access to systems and sensitive data, allowing them to leverage the compromised environment for malicious activities.

  2. Data Leakage: The vulnerability could lead to significant data breaches, exposing confidential information to unauthorized parties and resulting in potential regulatory and legal penalties.

  3. System Compromise: Successful exploitation of this vulnerability may allow full control over affected systems, potentially leading to widespread system disruptions or the deployment of malware, including ransomware.

Affected Version(s)

FAST LTA Silent Brick WebUI Linux WebUI Release 2.45 (Linux 5.4.109-gentoo-FAST) < 2.63.04

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stefan Mettler from CRYPTRON Security GmbH
.