WaveStore WaveView Client Path Traversal Vulnerability Allowing Arbitrary Command Execution on WaveStore Server

Vulnerability

A path traversal vulnerability has been identified in the WaveView client, allowing high-privileged users to execute arbitrary operating system commands on the connected WaveStore Server. This issue arises in the 'showerr' script, where improper validation of file paths can be exploited. The vulnerability affects all versions of WaveStore Server prior to 6.44.44.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server, with potential for significant system compromise.

Remediation

Users can upgrade to WaveStore Server version 6.44.44 or later to address this vulnerability.

Added: Dec 16, 2025, 1:18 PM
Updated: Dec 16, 2025, 2:14 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.