HiveOS Vulnerabilities Let Attackers Execute Arbitrary Commands

Post Reply
Shane1145
Posts: 1189
Joined: Wed Sep 25, 2024 2:31 pm

HiveOS Vulnerabilities Let Attackers Execute Arbitrary Commands

Post by Shane1145 »

Security researchers have uncovered three critical vulnerabilities in Extreme Networks’ IQ Engine (HiveOS) that collectively enable authenticated attackers to escalate privileges, decrypt passwords, and execute arbitrary commands on affected systems.

The flaws—tracked as CVE-2025-27229, CVE-2025-27228, and CVE-2025-27227—were disclosed through coordinated efforts led by Lukas Schauer of Bonn-Rhein-Sieg University of Applied Sciences, prompting Extreme Networks to release patched firmware (version 10.7r5).

https://cybersecuritynews.com/hiveos-arbitrary-command/
Post Reply