Authenticated OS Command Injection Vulnerability in Cohesity TranZman Web Application
CVE-2025-67840
What is CVE-2025-67840?
Multiple OS command injection vulnerabilities exist in the TranZman web application API endpoints, particularly affecting authenticated admin users. By directly concatenating user inputs into system commands without proper sanitization, attackers can leverage these flaws to inject and execute arbitrary commands with root access. This can be exploited through legitimate API requests during processes like job creation or execution. An attacker can modify parameters to include shell metacharacters, enabling remote code execution and bypassing the CLISH restricted shell. As a result, the system can be fully compromised, affecting the security and integrity of the appliance. The vulnerabilities persist even in the latest patched version (TZM_1757588060_SEP2025_FULL.depot).
