PT-2025-26597 · Aviatrix · Aviatrix Controller

·

CVE-2025-2172

·

Published

2025-06-23

·

Updated

2025-07-31

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Aviatrix Controller versions prior to 7.1.4208 Aviatrix Controller versions prior to 7.2.5090 Aviatrix Controller versions prior to 8.0.0
Description: The issue is related to the failure of the Aviatrix Controller to sanitize user input before passing it to command line utilities. This allows command injection via special characters in filenames.
Recommendations: For versions prior to 7.1.4208, update to version 7.1.4208 or later. For versions prior to 7.2.5090, update to version 7.2.5090 or later. For versions prior to 8.0.0, update to version 8.0.0 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2172

Affected Products

Aviatrix Controller