EndRun Technologies Sonoma D12 Network Time Server OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability allowing unauthorized remote code execution has been identified in the EndRun Technologies Sonoma D12 Network Time Server (GPS) firmware version 6010-0071-000 v4.00. This vulnerability arises from improper handling of user input, which could be exploited to execute arbitrary commands on the server.

Impact

Exploitation of this vulnerability could lead to unauthorized remote code execution, privilege escalation, and full system compromise, requiring elevated privileges.

Remediation

The vendor has provided interim mitigation steps, which include disabling web-management access. These steps have been verified as effective by the vendor, but should be evaluated for operational impact before applying in production environments.

Added: Oct 6, 2025, 5:26 PM
Updated: Oct 6, 2025, 8:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.