VYPR
Critical severity9.1NVD Advisory· Published Jul 7, 2025· Updated Apr 15, 2026

CVE-2025-3626

CVE-2025-3626

Description

A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') while uploading a config file via webUI.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.