CVE-2025-60960
8.2EndRun Technologies · Sonoma D12 Network Time Server
An OS command injection vulnerability in the EndRun Technologies Sonoma D12 Network Time Server firmware version 4.00 allows unauthenticated attackers to execute arbitrary code.
Executive summary
An OS command injection vulnerability in the EndRun Technologies Sonoma D12 Network Time Server allows unauthenticated remote attackers to achieve arbitrary code execution and system compromise.
Vulnerability
This vulnerability is an OS command injection flaw that enables an unauthenticated, network-adjacent attacker to inject and execute arbitrary system commands. The vulnerability affects the device firmware, potentially leading to full system control, denial of service, or unauthorized access to sensitive information.
Business impact
The exploitation of this vulnerability poses a severe risk to organizational infrastructure, as the Sonoma D12 serves as a critical network time source. Successful exploitation could allow attackers to manipulate time-sensitive logs, bypass security controls that rely on accurate timestamps, or pivot into the internal network. With a CVSS score of 8.2, this high-severity flaw necessitates immediate attention to prevent unauthorized access and potential disruption of time-synchronization services.
Remediation
Immediate Action: Contact EndRun Technologies support or monitor the official vendor advisory portal for the release of a firmware patch addressing this command injection vulnerability.
Proactive Monitoring: Review device access logs for unusual command patterns or unauthorized connection attempts originating from untrusted network segments.
Compensating Controls: Restrict management interface access to the Sonoma D12 server via network segmentation or firewall rules to ensure only authorized administrative hosts can communicate with the device.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical role of network time servers in maintaining security and logging integrity, this vulnerability must be treated with high priority. Organizations should isolate affected devices from public-facing networks until a firmware update is applied. Administrators should proactively engage with the vendor to obtain the necessary remediation and ensure their time-synchronization infrastructure is protected against unauthorized command execution.