CVE-2025-15349

7.5

Anritsu · ShockLine

A race condition vulnerability in the Anritsu ShockLine SCPI component allows unauthenticated network-adjacent attackers to achieve remote code execution.

Executive summary

A critical race condition in Anritsu ShockLine allows unauthenticated, network-adjacent attackers to execute arbitrary code on the target system.

Vulnerability

The vulnerability is a race condition (CWE-362) within the SCPI component caused by improper synchronization when accessing shared resources. An unauthenticated attacker can exploit this flaw to execute code in the context of the running process.

Business impact

Successful exploitation of this vulnerability results in full system compromise, as it allows for arbitrary code execution. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to operational integrity, potentially leading to unauthorized data access, system disruption, or the use of the device as a pivot point within the network.

Remediation

Immediate Action: Organizations should restrict network access to the SCPI interface to trusted segments only and monitor for vendor-provided updates via the official Anritsu support portal.

Proactive Monitoring: Security teams should review network logs for unusual traffic patterns targeting the SCPI management ports and monitor for unexpected process execution on the affected hardware.

Compensating Controls: Deploy network-level access control lists or virtual local area networks to isolate the ShockLine devices from untrusted network traffic, effectively preventing network-adjacent exploitation.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

This vulnerability presents a significant risk due to the lack of required authentication for exploitation. While no patch is currently confirmed, administrators must prioritize network isolation for all affected ShockLine devices to mitigate the risk of unauthorized access. Continuous monitoring of the vendor advisory is essential to ensure the immediate application of security updates once they become available.

More Anritsu CVEs

Sources