Wazuh Agent and Manager OS Command Injection and Untrusted Search Path
Vulnerability Description
Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags, and Kaspersky AR script parameters. Attackers can exploit these vulnerabilities by injecting malicious commands through configuration files, SMTP server settings, and custom flags to achieve remote code execution on affected systems.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-15616
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Published by @vikman90.
- Pedro Nicolas Gomez Palacios (Nicogp)
References
More from Wazuh
View All →Affected Vendor
Wazuh
View all reports →