CVE-2025-23237: I-O Data Device, Inc Ud-LT2

Medium severity, CVSS 6.6. EPSS: 0.9% chance of exploitation in the next 30 days.

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.

Affected products

Published 2025-01-22. Last modified 2026-06-17.