CVE-2025-23237: I-O Data Device, Inc Ud-LT2
Medium severity, CVSS 6.6. EPSS: 0.9% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. If a user logs in to CLI of the affected product, an arbitrary OS command may be executed.
Affected products
- I-O Data Device, Inc Ud-LT2: up to and including 1.00.008_SE
Published 2025-01-22. Last modified 2026-06-17.