[Japanese]
|
JVNDB-2025-000020
|
+F FS010M vulnerable to OS command injection
|
+F FS010M provided by FUJI SOFT INCORPORATED contains multiple OS command injection vulnerabilities listed below.
- OS command injection (CWE-78) - CVE-2025-24306
- OS command injection (CWE-78) - CVE-2025-25220
Takeshi Kuramori of National Institute of Information and Communications Technology, Cybersecurity Research Institute reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 8.8 (High) [IPA Score]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2025-25220
|
CVSS V3 Severity:
Base Metrics:7.2 (High) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2025-24306
|
|
FUJISOFT INCORPORATED
- +F FS010M versions prior to V2.0.0_1101(CVE-2025-24306)
- +F FS010M versions prior to V2.0.1_1101(CVE-2025-25220)
|
|
- An arbitrary OS command may be executed by a remote authenticated attacker with an administrative privilege. (CVE-2025-24306)
- An arbitrary OS command may be executed by a remote authenticated attacker. (CVE-2025-25220)(CVE-2025-25220)
|
[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
The developer has released the updates listed below that address these vulnerabilities.
CVE-2025-24306
CVE-2025-25220
|
FUJISOFT INCORPORATED
|
- OS Command Injection(CWE-78) [IPA Evaluation]
|
- CVE-2025-24306
- CVE-2025-25220
|
- JVN : JVN#11230428
|
- [2025/03/18]
Web page was published
|