PT-2026-29240 · Cato Networks · Cato Networks Socket
CVE-2025-14213
·
Published
2026-03-31
·
Updated
2026-07-25
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
Cato Networks Socket versions prior to 25
Description
An authenticated attacker with access to the Socket web interface (UI) can execute arbitrary operating system commands as the root user on the Socket’s internal system. The issue is a command injection. The affected component is the Socket web interface. The attacker needs to be authenticated to exploit this issue.
Recommendations
Update Cato Networks Socket to version 25 or later.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cato Networks Socket