Blue Angel Software Suite (5V Technologies) - OS Command Injection
CVE-2025-34033
Early Release
Description
Blue Angel 5V Technologies Blue Angel Software Suite through 20230920, as used in Analog Telephone Adapter (ATA) and Voice over IP (VoIP) devices, allows remote authenticated attackers to execute arbitrary OS commands as root via shell metacharacters in the ping_addr parameter to webctrl.cgi?action=pingtest_update.
Severity
High
CVSS Score
8.8
Affected Product
blue_angel_software_suite
Published Date
August 13, 2026
Template Author
princechaddha, ritikchaddha
CVE-2025-34033.yaml
8.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-34033
CWE ID:
cwe-78
Remediation Steps
Change default credentials, block management ports (e.g. 9000), update firmware, and restrict admin access to trusted networks.