CVE-2025-0457: Netvision Information Airpass
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
Affected products
- Netvision Information Airpass: from 2.9.0, before 2.9.0.241231 (fixed in 2.9.0.241231); from 3.0.0, before 3.0.0.241231 (fixed in 3.0.0.241231)
Published 2025-01-16. Last modified 2026-06-17.