Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-34112
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE
Source: NVD (National Vulnerability Database)
Vulnerability Description
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the appliance database. This user can then trigger a command injection vulnerability in the '/index.php?page=licenses' endpoint to execute arbitrary commands. The attacker may escalate privileges to root by exploiting an insecure sudoers configuration that allows the 'mazu' user to execute arbitrary commands as root via SSH key extraction and command chaining. Successful exploitation allows full remote root access to the virtual appliance.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Riverbed SteelCentral NetProfiler 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Riverbed SteelCentral NetProfiler是美国Riverbed公司的一个网络性能管理软件。 Riverbed SteelCentral NetProfiler 10.8.7版本存在安全漏洞,该漏洞源于SQL注入和命令注入,可能导致远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Riverbed TechnologySteelCentral NetExpress 10.8.7 -
Riverbed TechnologySteelCentral NetProfiler 10.8.7 -
II. Public POCs for CVE-2025-34112
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-34112
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-34112

No comments yet


Leave a comment