CVE-2025-15351

7.8

Anritsu · VectorStar

A deserialization of untrusted data vulnerability in the Anritsu VectorStar CHX file parser allows for remote code execution when a user opens a malicious file.

Executive summary

An insecure deserialization vulnerability in Anritsu VectorStar allows a remote attacker to achieve arbitrary code execution on the host system.

Vulnerability

The vulnerability exists due to improper validation of user-supplied data during the parsing of CHX files, which leads to insecure deserialization. An unauthenticated attacker can exploit this by enticing a user to open a specially crafted CHX file, resulting in code execution within the context of the current process.

Business impact

The ability for an attacker to execute arbitrary code on a system poses a severe risk to organizational security, potentially leading to full system compromise, data theft, or the installation of persistent malicious software. Given the CVSS score of 7.8, this vulnerability is classified as High severity, reflecting the significant impact on confidentiality, integrity, and availability should an exploit be successful.

Remediation

Immediate Action: Users should exercise caution and avoid opening CHX files from untrusted or unknown sources until an official security patch is released and applied.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process spawning or unauthorized file access originating from the VectorStar application.

Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious child processes initiated by the VectorStar software suite.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a significant risk because it enables remote code execution through common user interaction. Organizations utilizing Anritsu VectorStar should restrict the handling of CHX files to trusted sources and monitor for vendor communication regarding a permanent patch. Prioritize this update immediately upon its release to close the identified attack vector.

More Anritsu CVEs

Sources