Command Injection Vulnerability in Aviatrix Controller Products
CVE-2025-2172

7.5HIGH

Key Information:

Vendor

Aviatrix

Vendor
CVE Published:
23 June 2025

What is CVE-2025-2172?

Aviatrix Controller versions preceding 7.1.4208, 7.2.5090, and 8.0.0 improperly handle user input by failing to adequately sanitize it before utilizing it in command line utilities. This flaw allows attackers to exploit special characters in filenames to execute arbitrary commands, potentially compromising system integrity and security. Organizations using affected versions should prioritize patching and review their input validation protocols to mitigate the risk associated with this vulnerability.

Affected Version(s)

Controller 7.1.4208

Controller 7.1.4208

Controller 7.2.5090

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2172 : Command Injection Vulnerability in Aviatrix Controller Products