N-Partner N-Reporter, N-Cloud, and N-Probe OS Command Injection Vulnerability
Vulnerability
An OS command injection vulnerability has been identified in N-Partner's N-Reporter, N-Cloud, and N-Probe applications. This vulnerability allows authenticated remote attackers to inject arbitrary operating system commands, which are then executed on the server.
Impact
Exploitation of this vulnerability could lead to unauthorized command execution on the server, allowing attackers to execute arbitrary code with the privileges of the application or service running the commands.
Remediation
Users are advised to update to the latest version of the affected applications. For NCG-2510WG-LTE (EU/US), update to version 1.0_20250811 or later. For ICG-2510W-LTE (EU/US), also update to version 1.0_20250811 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
