CVE-2025-60956
8.0EndRun Technologies · Sonoma D12 Network Time Server (GPS)
A Cross Site Request Forgery (CSRF) vulnerability in the EndRun Technologies Sonoma D12 Network Time Server allows unauthorized actions, including code execution and information disclosure.
Executive summary
A Cross Site Request Forgery vulnerability in the EndRun Technologies Sonoma D12 Network Time Server poses a significant risk to critical infrastructure integrity and system availability.
Vulnerability
This vulnerability is a Cross Site Request Forgery (CSRF) flaw that allows a remote, authenticated attacker with low privileges to trigger unauthorized actions on the device. By inducing a user to perform an action, the attacker can achieve remote code execution, cause a denial of service, escalate privileges, or exfiltrate sensitive data.
Business impact
The Sonoma D12 serves as a critical time synchronization component for enterprise networks. Successful exploitation of this flaw could allow an attacker to disrupt time synchronization services, potentially leading to widespread authentication failures or system instability across the environment. Given the high CVSS score of 8.0, this represents a significant risk to operational continuity and data security.
Remediation
Immediate Action: Contact EndRun Technologies support immediately to obtain the specific firmware patch that addresses this CSRF vulnerability.
Proactive Monitoring: Review device access logs for unusual administrative activity or requests originating from unexpected IP addresses.
Compensating Controls: Restrict management interface access to specific, trusted administrative IP ranges using internal network segmentation or a hardware firewall.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations utilizing the EndRun Technologies Sonoma D12 should prioritize this advisory and reach out to the vendor for the necessary firmware update. Given the high severity of the potential impact, including remote code execution, ensure that the management interface of this device is not exposed to the public internet and is strictly isolated within the internal management network.