S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jun 13, 2025

CVE-2025-4009 Scanner

CVE-2025-4009 Scanner - Remote Code Execution (RCE) vulnerability in Evertz SDVN 3080ipx-10G

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.4k
Times Used
continuous scan runs
5.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-4009
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management interface can be used by administrators to control product features, setup network switching, and register license among other features. The application has been developed in PHP with the webEASY SDK, also named ‘ewb’ by Evertz. This web interface has two endpoints that are vulnerable to arbitrary command injection (CVE-2025-4009, CVE-2025-10364) and the authentication mechanism has a flaw leading to authentication bypass (CVE-2025-10365). CVE-2025-4009 covers the command injection in feature-transfer-import.php CVE-2025-10364 covers the command injection in feature-transfer-export.php Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. This level of access could lead to serious business impact such as the interruption of media streaming, modification of media being streamed, alteration of closed captions being generated, among others.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
3080ipx-10Gby Evertz
0
MViP-IIby Evertz
0
cVIPby Evertz
0
7890IXGby Evertz
0
Updated Aug 22, 2026View on NVD →
Detail

The Evertz SDVN 3080ipx-10G is utilized in high-bandwidth video switching applications. Professionals in broadcasting and streaming services implement this device for its capability to manage various network configurations and media streaming functions. The device features a web management interface where administrators can control settings related to video transmission and switch management. It runs on a PHP-based system with the webEASY SDK, which is integral for media professionals looking to integrate with existing network infrastructures. The Evertz SDVN 3080ipx-10G is vital for operations demanding reliable media distribution and intricate network assignments, particularly in studios and live events. This makes it a cornerstone for media distribution infrastructure, widely adopted due to its robust functionality and control features.

The vulnerability in question arises from arbitrary command injection via two exposed endpoints within the web management interface. These endpoints inadvertently allow remote unauthenticated users to execute commands as the root user, leading to a comprehensive security threat. With such vulnerabilities, attackers can perform unauthorized actions which may compromise system integrity and availability. This security flaw was identified due to improper input validation and insufficient authentication mechanisms on affected devices. Command injection weaknesses allow exploitation, granting malicious actors access to execute arbitrary commands, potentially altering system operations. Such vulnerabilities have substantial implications, particularly where sensitive media and network information is involved, necessitating immediate security audits.

Technically, the vulnerability is present in the PHP-based endpoints of the Evertz SDVN platform. Attackers can exploit these via crafted HTTP requests that bypass authentication checks. Specifically, a payload embedded in the query string is mishandled, granting elevated permissions that should not be accessible to unauthenticated users. By targeting the HTTP GET requests for specific PHP scripts, adversaries can gain unauthorized access. The vulnerable endpoints fail to adequately filter and sanitize incoming requests, facilitating command injection. This design flaw is further compounded by the exposed nature of the service, making it feasible for attackers to automate the exploitation of these vulnerabilities over the network.

Successful exploitation of this vulnerability could severely disrupt operations. Potential effects include unauthorized access to critical media control systems, interruption of media streams, or manipulation of streamed content. Such actions could impact service delivery, resulting in downtime or distorted media output. Financial and reputational damage can ensue from prolonged downtime and data breaches. Given that these systems often operate in real-time environments, any unplanned disruptions could significantly impair business operations. Additionally, access to internal networks and data poses serious threats to confidentiality and integrity.

REFERENCES

Solution Advice
  • Implement strict input validation and output encoding to prevent arbitrary command execution.
  • Enhance authentication and session management to ensure only authorized users can interact with critical endpoints.
  • Regularly update and patch the system software to address known vulnerabilities promptly.
  • Conduct security audits and penetration testing to identify and address potential vulnerabilities.
  • Deploy network intrusion detection systems to monitor and prevent potential exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.