CVE-2025-14213 is a command injection vulnerability affecting Cato Networks’ Socket versions prior to 25, allowing an authenticated attacker with web interface access to execute arbitrary operating system commands as the root user. Rated 8.3 HIGH on CVSS, this vulnerability is remotely exploitable with low attack complexity, requiring high privileges for execution, and can lead to high impact on confidentiality and availability. Currently, there is no evidence of active exploitation, no public exploit code available, and minimal community discussion, indicating a low immediate threat despite its high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Cato Networks | Socket | 24 and belowCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.