CVE-2025-60964: Endruntechnologies Sonoma d12 Firmware

Critical severity, CVSS 9.1. EPSS: 1.2% chance of exploitation in the next 30 days.

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and possibly other unspecified impacts.

Affected products

Published 2025-10-06. Last modified 2026-07-05.