Junglewise Threat Intelligence

CVE-2025-14213: Cato Networks Socket command injection in web interface

CVE-2025-14213 · Severity: info · CVSS 8.3 · Published 2026-03-31

Executive brief

Cato Networks Sockets, which are hardware or virtual appliances used to connect branch offices to the corporate network, contain a security flaw in their management interface. An authorized user with administrative access to the device's web interface can exploit this flaw to take full control of the underlying operating system. This could lead to a complete compromise of the appliance, allowing an attacker to disrupt network traffic or gain a foothold within the corporate infrastructure.

Technical details

A command injection vulnerability (CWE-78) exists in the web interface (UI) of Cato Networks Socket appliances due to improper input validation (CWE-20). An authenticated attacker with high privileges (PR:H) can reach the vulnerable component over the network and inject malicious commands into system calls. Successful exploitation allows for arbitrary code execution with root-level privileges on the underlying Linux-based operating system. The vulnerability is addressed in Socket version 25 and later.

Affected products

  • Cato Networks Socket Versions prior to 25

Timeline

  • 2026-03-31: disclosed
  • 2026-03-31: advisory

References