Metrics
Affected Vendors & Products
Tue, 30 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iwt facesentry Access Control System Firmware
|
|
| CPEs | cpe:2.3:h:iwt:facesentry_access_control_system:-:*:*:*:*:*:*:* cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.0:*:*:*:*:*:*:* cpe:2.3:o:iwt:facesentry_access_control_system_firmware:5.7.2:*:*:*:*:*:*:* cpe:2.3:o:iwt:facesentry_access_control_system_firmware:6.4.8:*:*:*:*:*:*:* |
|
| Vendors & Products |
Iwt facesentry Access Control System Firmware
|
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Iwt
Iwt facesentry Access Control System |
|
| Vendors & Products |
Iwt
Iwt facesentry Access Control System |
Fri, 26 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters. | |
| Title | FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:23:05.664Z
Reserved: 2025-12-24T14:27:12.476Z
Link: CVE-2019-25243
Updated: 2025-12-24T20:03:50.105Z
Status : Analyzed
Published: 2025-12-24T20:15:52.310
Modified: 2025-12-30T20:19:32.513
Link: CVE-2019-25243
No data.