Back to Database
Status published
Medium
CVE-2025-23237
Improper neutralization of special elements used in an OS command...
Vulnerability Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-23237
Credits & Attribution
No credits recorded in the NVD database.
References
More from I-O DATA DEVICE, INC.
View All →CVE-2025-61865
Multiple NAS management applications provided by I-O DATA DEVICE, INC....
High
8.4
CVE-2025-58116
Improper neutralization of special elements used in an OS command...
High
8.6
CVE-2025-55075
Hidden functionality issue exists in WN-7D36QR and WN-7D36QR/UE. If this...
Medium
6.9
CVE-2025-32738
Missing authentication for critical function issue exists in I-O DATA...
Medium
6.9
CVE-2025-32002
Improper neutralization of special elements used in an OS command...
Critical
9.3
Affected Vendor
I-O DATA DEVICE, INC.
View all reports →Affected Software
UD-LT2
Vulnerable Versions:
firmware Ver.1.00.008_SE and earlier
Timeline
Official Publish:
January 22nd, 2025
Last Modified:
February 12th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H