CVE-2025-11546: Nec Corporation Clusterpro X For Linux Expresscluster X For Linux

Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.

CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication.

Affected products

  • Nec Corporation Clusterpro X For Linux Expresscluster X For Linux
  • Nec Corporation Clusterpro X Singleserversafe For Linux Expresscluster X Singleserversafe For Linux

Published 2025-11-07. Last modified 2026-06-17.