CVE-2025-60956: Endruntechnologies Sonoma d12 Firmware

High severity, CVSS 8.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.

Affected products

Published 2025-10-06. Last modified 2026-07-05.