CVE-2025-15349 is a Remote Code Execution (RCE) vulnerability affecting Anritsu ShockLine products, stemming from a race condition in the SCPI component. This high-severity flaw (CVSS 7.5) allows unauthenticated, network-adjacent attackers to execute arbitrary code due to improper locking during object operations. While there is no public exploit code, active exploitation, or significant community discussion reported, the potential for full system compromise makes this a critical concern for affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2025.4.1CPE matchmatch criteria | cpe:2.3:a:anritsu:shockline:2025.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.