CVE-2025-15350
7.8Anritsu · VectorStar
Anritsu VectorStar is vulnerable to remote code execution via insecure deserialization of untrusted CHX files, requiring user interaction to trigger the parsing flaw.
Executive summary
A remote code execution vulnerability in Anritsu VectorStar allows attackers to execute arbitrary code through the parsing of malicious CHX files.
Vulnerability
This vulnerability involves the insecure deserialization of untrusted data within the CHX file parsing process (CWE-502). The flaw allows an attacker to achieve remote code execution in the context of the current process, provided the user is tricked into opening a malicious file.
Business impact
The ability for an attacker to execute arbitrary code on a target system poses a severe risk to data integrity, confidentiality, and system availability. Given the CVSS score of 7.8, this vulnerability is classified as High severity. Successful exploitation could lead to total system compromise, potentially allowing unauthorized access to sensitive test data or control over the instrument hardware.
Remediation
Immediate Action: Users should exercise extreme caution when opening unknown or untrusted CHX files and verify the source of all files before processing them in VectorStar. Since a specific patch version is currently unknown, contact Anritsu support or check the official vendor advisory for the latest firmware or software updates.
Proactive Monitoring: Security teams should monitor system logs for unusual process execution patterns or abnormal file access events originating from the VectorStar software environment.
Compensating Controls: Deploy endpoint security solutions capable of identifying and blocking malicious file execution attempts, and restrict file access permissions for the application to the minimum necessary level.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
This vulnerability represents a significant security risk for Anritsu VectorStar installations. Administrators must prioritize the identification of affected systems and maintain strict control over the handling of CHX files until a vendor-supplied patch is identified and applied. Monitoring for software updates from Anritsu is essential to ensure long-term remediation.