OS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS command may be executed by a remote attacker who can log in to the product.
CVE ID: CVE-2025-25053
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor: Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd., Inaba Denki Sangyo Co., Ltd.
Product: AC-WPS-11ac, AC-WPS-11ac-P, AC-WPSM-11ac, AC-WPSM-11ac-P, AC-PD-WPS-11ac, AC-PD-WPS-11ac-P
EPSS Score: 0.25% (probability of being exploited)
EPSS Percentile: 48.13% (scored less or equal to compared to others)
EPSS Date: 2025-04-21 (when was this score calculated)