CVE-2025-0415 - CVE House
Back to Database
Status published Critical CVE-2025-0415

Command Injection in NTP Setting

Vulnerability Description

A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system commands through the NTP settings. Successful exploitation may result in the device entering an infinite reboot loop, leading to a total or partial denial of connectivity for downstream systems that rely on its network services.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0415

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

EDF-G1002-BP Series, EDR-810 Series, EDR-8010 Series, EDR-G9004 Series, EDR-G9010 Series, OnCell G4302-LTE4 Series, TN-4900 Series, NAT-102 Series
Vulnerable Versions:
1.0

Timeline

Official Publish: April 2nd, 2025
Last Modified: April 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)