CVE-2025-10239
7.2Progress Software · Flowmon
A command injection vulnerability in Progress Software Flowmon allows authenticated administrators to execute unauthorized OS commands via troubleshooting scripts.
Executive summary
A command injection vulnerability in Progress Software Flowmon, affecting versions prior to 12.5.5, allows authenticated administrators to execute unauthorized system commands.
Vulnerability
This is an OS command injection flaw (CWE-78) occurring within scripts intended for troubleshooting. It requires an attacker to have administrator privileges and access to the management interface to trigger the vulnerability.
Business impact
The ability to execute arbitrary OS commands poses a severe risk to the integrity and availability of the Flowmon appliance. With a CVSS score of 7.2, this high-severity vulnerability could allow an attacker to gain full control over the management system, leading to potential data exfiltration, lateral movement within the network, or complete service disruption.
Remediation
Immediate Action: Upgrade to Flowmon version 12.5.5 or later as specified in the Progress Software security advisory.
Proactive Monitoring: Review management interface access logs for unusual administrative activity or unexpected execution of system scripts.
Compensating Controls: Restrict access to the management interface to authorized personnel only, utilizing network-level access control lists or VPNs to minimize exposure to untrusted networks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for OS command injection, administrators should prioritize updating their Flowmon appliances to version 12.5.5 immediately. Limiting administrative access to the management console remains a critical defense-in-depth strategy to mitigate the risk of unauthorized command execution while the update is being deployed.
More Progress Software CVEs
Sources
Originally found and disclosed by This vulnerability was discovered by Kentaro Kawane., per the CVE Program record.