CVE-2025-0680 Details
Description
Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.
A command injection vulnerability has been identified in New Rock Technologies Cloud Connected Devices, including the OM500 IP-PBX, MX8G VoIP Gateway, and NRP1302/P Desktop IP Phone, all versions. This vulnerability allows remote attackers to take control of devices connected to the cloud by improperly handling special elements in the device cloud RPC command process.
New Rock Technologies has not responded to requests for collaboration with CISA to address these vulnerabilities. Users are encouraged to contact New Rock Technologies customer support for more information. CISA recommends minimizing network exposure for control system devices, using firewalls to isolate control system networks from business networks, and employing secure remote access methods such as VPNs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 30, 2025CISA-ADP
Assessed Jan 30, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-030-02 | [email protected] | AdvisoryBundleRemedy |
| https://www.newrocktech.com/ContactUs/index.html | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| New Rock Technologies OM500 IP-PBX | All versions |
CPE
Remediation
| |
| New Rock Technologies MX8G VoIP Gateway | All versions |
CPE
Remediation
| |
| New Rock Technologies NRP1302/P Desktop IP Phone | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 30, 2025 | New CVE Received | [email protected] |
Volerion