CVE-2025-34112

CRITICAL EPSS 78.2%
Published Jul 15, 202511mo ago · Modified Jun 17, 20261w ago
10.0 CVSS 4.0
Critical
Find Similar
Published Jul 15, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago

Description

An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the appliance database. This user can then trigger a command injection vulnerability in the '/index.php?page=licenses' endpoint to execute arbitrary commands. The attacker may escalate privileges to root by exploiting an insecure sudoers configuration that allows the 'mazu' user to execute arbitrary commands as root via SSH key extraction and command chaining. Successful exploitation allows full remote root access to the virtual appliance.

CVSS Details

Base Score
10.0
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
78.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 4

CWE-266
CWE-306 Missing Authentication for Critical Function Authentication
CWE-78 OS Command Injection Injection
CWE-89 SQL Injection Injection

References 4

  • raw.githubusercontent.com https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/riverbed_netprofiler_netexpress_exec.rb
  • support.riverbed.com https://support.riverbed.com/content/support/software/steelcentral-npm/net-profiler.html
  • exploit-db.com https://www.exploit-db.com/exploits/40108
  • vulncheck.com https://www.vulncheck.com/advisories/riverbed-steel-central-net-profiler-net-express-rce

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.