HIGH
VA MAX
CVE published 2026-04-05
CVE-2019-25671
CVE-2019-25671 is a remote code execution vulnerability in VA MAX 8.3.4. Authenticated attackers can execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter via POST requests to the changeip.php endpoint. This vulnerability has a high CVSS score of 8.7, indicating high severity. Security teams and administrators should be aware of this vulnerability and take steps to mitigate it.