CVE-2025-60963

8.2

EndRun Technologies · Sonoma D12 Network Time Server

An OS command injection vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server, allowing unauthenticated attackers to execute arbitrary code and gain escalated privileges.

Executive summary

An unauthenticated OS command injection vulnerability in the EndRun Technologies Sonoma D12 Network Time Server poses a high risk of system compromise and privilege escalation.

Vulnerability

This vulnerability is an OS command injection flaw that enables an unauthenticated, remote attacker to execute arbitrary system commands. The lack of input validation on the affected firmware allows for full administrative privilege escalation and sensitive information disclosure.

Business impact

The potential for unauthenticated remote code execution represents a significant threat to organizational integrity. Given the 8.2 CVSS score, this vulnerability could allow attackers to gain full control over network time infrastructure, leading to unauthorized data access, system disruption, or manipulation of time-sensitive security logs.

Remediation

Immediate Action: Contact EndRun Technologies support to obtain the latest firmware update for the Sonoma D12 unit. If a patch is unavailable, isolate the device from external network access to prevent remote exploitation.

Proactive Monitoring: Review device access logs for unauthorized administrative logins or unusual command execution patterns originating from unexpected IP addresses.

Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the device management interface to known, trusted management workstations.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit or weaponized code available for this vulnerability.

Analyst recommendation

The severity of this vulnerability necessitates prompt attention, as it allows for complete system compromise without prior authentication. Security teams should prioritize identifying all affected Sonoma D12 units within the network and apply the vendor-provided firmware update as soon as it becomes available to mitigate the risk of unauthorized access.

Sources