CVE-2025-64444: Sony Network Communications Inc Ncp-HG100/CELLULAR Model
High severity, CVSS 8.6. EPSS: 1.2% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS command with root privileges.
Affected products
- Sony Network Communications Inc Ncp-HG100/CELLULAR Model: up to and including 1.4.48.16
- Sony Network Communications Inc Ncp-HG100/WLAN Model: up to and including 1.4.48.16
Published 2025-11-14. Last modified 2026-06-17.