PatchSiren

VA MAX CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH VA MAX CVE published 2026-04-05

CVE-2019-25671

CVE-2019-25671 is a remote code execution vulnerability in VA MAX 8.3.4. Authenticated attackers can execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter via POST requests to the changeip.php endpoint. This vulnerability has a high CVSS score of 8.7, indicating high severity. Security teams and administrators should be aware of this vulnerability and take steps to mitigate it.