CVE-2025-2172

Publication date

2025-06-23 14:01:19

Family

Mandiant

State

PUBLISHED

Description

Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames