CVE-2025-25504: Niceforyou Gefen Webfwc

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over TCP port 4444 without authentication and execute arbitrary commands with root privileges.

Affected products

  • Niceforyou Gefen Webfwc: version 1.70v only; version 1.85h only; version 1.86v only

Published 2025-05-05. Last modified 2026-07-05.