CVE-2025-13442 is a critical command injection vulnerability affecting UTT 进取 750W firmware up to version 3.2.2-191225. Specifically, the /goform/formPdbUpConfig function is vulnerable to manipulation of the 'policyNames' argument. This flaw allows for remote, unauthenticated attackers to execute arbitrary commands on the device. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The vendor has not responded to disclosure attempts. Exploit code for CVE-2025-13442 has been publicly disclosed, increasing the likelihood of exploitation, though it is not yet listed in the CISA KEV catalog. Community discussion is notably high, indicating significant awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.2-191225CPE matchmatch criteria | cpe:2.3:o:utt:750w_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.