CVE-2025-10239

7.2

Progress Software · Flowmon

A command injection vulnerability in Progress Software Flowmon allows authenticated administrators to execute unauthorized OS commands via troubleshooting scripts.

Executive summary

A command injection vulnerability in Progress Software Flowmon, affecting versions prior to 12.5.5, allows authenticated administrators to execute unauthorized system commands.

Vulnerability

This is an OS command injection flaw (CWE-78) occurring within scripts intended for troubleshooting. It requires an attacker to have administrator privileges and access to the management interface to trigger the vulnerability.

Business impact

The ability to execute arbitrary OS commands poses a severe risk to the integrity and availability of the Flowmon appliance. With a CVSS score of 7.2, this high-severity vulnerability could allow an attacker to gain full control over the management system, leading to potential data exfiltration, lateral movement within the network, or complete service disruption.

Remediation

Immediate Action: Upgrade to Flowmon version 12.5.5 or later as specified in the Progress Software security advisory.

Proactive Monitoring: Review management interface access logs for unusual administrative activity or unexpected execution of system scripts.

Compensating Controls: Restrict access to the management interface to authorized personnel only, utilizing network-level access control lists or VPNs to minimize exposure to untrusted networks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for OS command injection, administrators should prioritize updating their Flowmon appliances to version 12.5.5 immediately. Limiting administrative access to the management console remains a critical defense-in-depth strategy to mitigate the risk of unauthorized command execution while the update is being deployed.

More Progress Software CVEs

Sources

Originally found and disclosed by This vulnerability was discovered by Kentaro Kawane., per the CVE Program record.