CVE-2025-14213 - CVE House
Back to Database
Status published High CVE-2025-14213

Cato's Socket WebUI is vulnerable to OS Command Injection

Vulnerability Description

Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attacker with access to the Socket web interface (UI) to execute arbitrary operating system commands as the root user on the Socket’s internal system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14213

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Cato Networks

View all reports →

Affected Software

Socket
Vulnerable Versions:
24 and below

Timeline

Official Publish: March 31st, 2026
Last Modified: March 31st, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)