CVE-2025-64444 HIGH

CVE-2025-64444

Vendor Sony Network Communications Inc.
Product NCP-HG100/Cellular model
Weakness CWE-78
Published November 14, 2025
Last update November 14, 2025

CVSS base score

7.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4.48.16 and earlier. If exploited, a remote attacker who has obtained the authentication information to log in to the management page of the product may execute an arbitrary OS command with root privileges.

Key dates

02Disclosure timeline

November 14, 2025 CVE published
November 14, 2025 Record updated