Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 10 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anhui Seeker Electronic Technology Co., Ltd.
Anhui Seeker Electronic Technology Co., Ltd. xikestor Sks8310-8x |
|
| Vendors & Products |
Anhui Seeker Electronic Technology Co., Ltd.
Anhui Seeker Electronic Technology Co., Ltd. xikestor Sks8310-8x |
Sat, 07 Mar 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. Attackers can inject malicious commands through the destIp parameter to achieve remote code execution with root privileges on the network switch. | |
| Title | XikeStor SKS8310-8X PingTestSet Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-10T17:58:52.495Z
Reserved: 2026-01-28T21:47:35.120Z
Link: CVE-2026-25070
Updated: 2026-03-10T17:45:06.650Z
Status : Awaiting Analysis
Published: 2026-03-07T01:15:57.427
Modified: 2026-03-09T13:35:34.633
Link: CVE-2026-25070
No data.
OpenCVE Enrichment
Updated: 2026-03-09T10:06:12Z