Improper Verification of Source of a Communication Channel
CVE-2025-9999
Summary
Some payload elements of the messages sent between two stations in a networking architecture are not properly checked on the receiving station allowing an attacker to execute unauthorized commands in the application.
- HIGH
- ADJACENT
- NONE
- NONE
CWE-940 - Improper Verification of Source of a Communication Channel
The software establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.
References
Advisory Timeline
- Published