Command Injection Vulnerability in UNI-NMS-Lite by UNI
CVE-2025-46271

9.3CRITICAL

Key Information:

Vendor
CVE Published:
24 April 2025

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2025-46271?

UNI-NMS-Lite, a network management system from UNI, is susceptible to a command injection vulnerability. This issue allows unauthenticated attackers to execute arbitrary commands, posing a risk of unauthorized access and manipulation of sensitive device data. Proper security measures and timely updates are essential to mitigate this risk and protect network integrity.

Affected Version(s)

NMS-1000V All versions

NMS-500 All versions

UNI-NMS-Lite 0 <= 1.0b211018

News Articles

Multiple Critical Vulnerabilities in Planet Technology Industrial Networking Products

Planet Technology has released security updates addressing multiple critical vulnerabilities affecting their Industrial Networking products. Users and...

CISA Issues Warning Over Planet Technology Network Product Flaws

The flaws, if left unpatched, could allow remote attackers to take full control of affected devices, manipulate sensitive data.

Planet Technology Industrial Switch Flaws Risk Full Takeover - Patch Now

Immersive have discovered critical vulnerabilities in Planet Technology network management and switch products, allowing full device control.

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by Hackread

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kev Breen of Immersive reported these vulnerabilities to CISA.
.
CVE-2025-46271 : Command Injection Vulnerability in UNI-NMS-Lite by UNI