/Vulnerability Library

Blue Angel Software Suite (5V Technologies) - OS Command Injection

CVE-2025-34033
Early Release

Description

Blue Angel 5V Technologies Blue Angel Software Suite through 20230920, as used in Analog Telephone Adapter (ATA) and Voice over IP (VoIP) devices, allows remote authenticated attackers to execute arbitrary OS commands as root via shell metacharacters in the ping_addr parameter to webctrl.cgi?action=pingtest_update.

Severity

High

CVSS Score

8.8

Affected Product

blue_angel_software_suite

Published Date

August 13, 2026

Template Author

princechaddha, ritikchaddha

CVE-2025-34033.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-34033
CWE ID:
cwe-78

References

https://www.exploit-db.com/exploits/46792https://nvd.nist.gov/vuln/detail/CVE-2025-34033http://www.5vtechnologies.com

Remediation Steps

Change default credentials, block management ports (e.g. 9000), update firmware, and restrict admin access to trusted networks.