CVE-2025-64444
7.2Sony Network Communications Inc. · NCP-HG100
A command injection vulnerability exists in Sony Network Communications Inc. NCP-HG100 devices that allows authenticated attackers to execute arbitrary OS commands with root privileges.
Executive summary
A critical OS command injection vulnerability in Sony NCP-HG100 devices allows authenticated attackers to gain full root-level control over the system.
Vulnerability
This is an OS Command Injection (CWE-78) flaw occurring within the device management interface. An attacker who has successfully authenticated to the management page can inject malicious commands that execute with root privileges on the underlying operating system.
Business impact
The ability for an attacker to execute arbitrary commands with root privileges represents a total compromise of the affected device. This could lead to unauthorized data access, the establishment of persistent backdoors, or the use of the device as a pivot point for further lateral movement within the network. Given the CVSS score of 7.2, this vulnerability poses a significant risk to organizational infrastructure and network integrity.
Remediation
Immediate Action: Review the official Sony support advisory for the latest firmware release and apply the update to all affected NCP-HG100 units immediately.
Proactive Monitoring: Monitor management interface access logs for unusual login patterns or suspicious command strings that deviate from standard administrative operations.
Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and utilize a network firewall to prevent unauthorized external access to the management port.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a severe risk by allowing an authenticated user to escalate their access to full system control. Administrators must prioritize the application of firmware updates as soon as they are made available by the vendor to prevent potential unauthorized system takeover. Until updates can be applied, ensure that management interfaces are isolated from public exposure to mitigate the risk of unauthorized access.