CVE-2025-65076 Details
Description
WaveView client allows users to execute restricted set of predefined commands and scripts on the connected WaveStore Server. A malicious attacker with high-privileges is able to read or delete any file on the server using path traversal in the ilog script. This script is being run with root privileges. This issue was fixed in version 6.44.44
A path traversal vulnerability has been identified in the WaveView client, which allows high-privileged users to read or delete any file on the connected WaveStore Server. This issue arises in the 'ilog' script, which is executed with root privileges. The vulnerability affects all versions of WaveStore Server prior to 6.44.44.
Users can upgrade to WaveStore Server version 6.44.44 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/en/posts/2025/12/CVE-2025-65074 | [email protected] | Third Party Advisory |
| https://www.wavestore.com/products/video-management-software | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wavestore video management software server | <= 6.42.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | Initial Analysis | [email protected] |
| Dec 16, 2025 | New CVE Received | [email protected] |