Command Injection Vulnerability in Aviatrix Controller Products
CVE-2025-2172
What is CVE-2025-2172?
Aviatrix Controller versions preceding 7.1.4208, 7.2.5090, and 8.0.0 improperly handle user input by failing to adequately sanitize it before utilizing it in command line utilities. This flaw allows attackers to exploit special characters in filenames to execute arbitrary commands, potentially compromising system integrity and security. Organizations using affected versions should prioritize patching and review their input validation protocols to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Controller 7.1.4208
Controller 7.1.4208
Controller 7.2.5090
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved