VYPR
Medium severity6.5NVD Advisory· Published May 5, 2025· Updated Jul 5, 2026

CVE-2025-25504

CVE-2025-25504

Description

An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:niceforyou:gefen_webfwc:1.70v:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:niceforyou:gefen_webfwc:1.70v:*:*:*:*:*:*:*
    • cpe:2.3:a:niceforyou:gefen_webfwc:1.85h:*:*:*:*:*:*:*
    • cpe:2.3:a:niceforyou:gefen_webfwc:1.86v:*:*:*:*:*:*:*
  • Gefen/WebFWCcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 1.85h, 1.86v, 1.70

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.