CVE-2025-60957: Endruntechnologies Sonoma d12 Firmware

Critical severity, CVSS 9.9. EPSS: 1.2% chance of exploitation in the next 30 days.

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.

Affected products

Published 2025-10-06. Last modified 2026-07-05.