CVE-2025-22470
BaseFortify
Publication date: 2025-08-06
Last updated on: 2025-08-06
Assigner: JPCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sato | cl4_6nx_j_plus | * |
| sato | cl4_6nx_plus | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability affects CL4/6NX Plus and CL4/6NX-J Plus (Japan model) devices with firmware versions prior to 1.15.5-r1. It allows an attacker to upload specially crafted dangerous files that can execute arbitrary Lua scripts on the system with root privileges.
How can this vulnerability impact me? :
The vulnerability can lead to full system compromise because an attacker can execute arbitrary code with root privileges. This can result in unauthorized control over the affected device, potentially leading to data theft, system disruption, or further attacks within the network.