CVE-2025-46418: Westermo Weos

High severity, CVSS 7.6. EPSS: 0.7% chance of exploitation in the next 30 days.

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

Affected products

  • Westermo Weos: from 5.24, before 6 (fixed in 6)

Published 2026-09-02. Last modified 2026-09-08.