CVE-2025-15348

7.8

Anritsu · ShockLine

Anritsu ShockLine is vulnerable to remote code execution due to improper deserialization of untrusted data during the parsing of CHX files, requiring user interaction to trigger the flaw.

Executive summary

Anritsu ShockLine contains a critical deserialization vulnerability that allows remote attackers to execute arbitrary code on the host system via malicious CHX files.

Vulnerability

This vulnerability involves the insecure deserialization of untrusted data within the CHX file parsing logic. It is an unauthenticated, local-vector vulnerability that requires user interaction, such as opening a specially crafted file, to execute code in the context of the current process.

Business impact

Successful exploitation of this deserialization flaw allows an attacker to achieve remote code execution, potentially leading to total system compromise. Given the CVSS score of 7.8, the risk to data integrity and system availability is high, as an attacker could gain persistent access or exfiltrate sensitive data stored within the testing environment.

Remediation

Immediate Action: Users should immediately restrict the opening of untrusted or externally sourced CHX files and monitor official Anritsu support channels for the release of a security patch.

Proactive Monitoring: Security teams should monitor system logs for abnormal process execution or unexpected file access patterns associated with the ShockLine application.

Compensating Controls: Implement file integrity monitoring and endpoint protection software to detect and block malicious file execution attempts, effectively mitigating the risk until a vendor update is applied.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability necessitates a proactive posture even in the absence of current active exploitation reports. Organizations utilizing Anritsu ShockLine should prioritize the identification of affected installations and implement strict file handling policies until a vendor-supplied update is available to remediate the deserialization defect.

More Anritsu CVEs

Sources