CVE-2025-60962

8.2

EndRun Technologies · Sonoma D12 Network Time Server

An OS command injection vulnerability in the EndRun Technologies Sonoma D12 Network Time Server allows unauthenticated attackers to potentially gain sensitive information and impact system integrity.

Executive summary

A critical OS command injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server allows unauthenticated remote attackers to compromise system information and integrity.

Vulnerability

The device suffers from an OS command injection vulnerability triggered via unauthenticated network access. This flaw allows an attacker to execute arbitrary commands at the operating system level, leading to unauthorized information disclosure and loss of integrity.

Business impact

The CVSS score of 8.2 (High) reflects the significant risk posed by this vulnerability, particularly because it is exploitable by unauthenticated remote attackers. Successful exploitation could lead to full exposure of sensitive system data, unauthorized configuration changes, and a complete loss of trust in the time synchronization services provided by the device.

Remediation

Immediate Action: Contact EndRun Technologies support immediately to determine if a firmware update or security patch is available for the affected Sonoma D12 unit.

Proactive Monitoring: Review system access logs for anomalous traffic patterns or unexpected command executions originating from unauthorized IP addresses.

Compensating Controls: Isolate the affected time server on a restricted management VLAN and implement strict firewall rules to ensure only authorized devices can access the management interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for total system impact, administrators must prioritize the securing of these devices. If a firmware patch is not yet available, immediate network segmentation is mandatory to prevent unauthorized remote access until the vendor provides a permanent resolution.

Sources