Executive brief
Aviatrix Controllers contain an OS command injection vulnerability in the /v1/api endpoint due to improper neutralization of shell metacharacters. An unauthenticated remote attacker can execute arbitrary code by sending malicious payloads in the cloud_type or src_cloud_type parameters.
Affected products
- Aviatrix Controller before 7.1.4191, 7.2.x before 7.2.4996
Timeline
- 2025-01-07: disclosed: Initial disclosure and NVD publication
- 2025-01-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-01-16: exploited: Reported as exploited in the wild