Junglewise Threat Intelligence

CVE-2025-46418: Westermo WeOS 5 OS command injection via media definition

CVE-2025-46418 · Severity: high · CVSS 7.6 · Published 2026-09-02

Executive brief

Westermo WeOS 5 is an industrial network operating system deployed in critical infrastructure including power grids, water treatment, and manufacturing facilities. An attacker with administrator credentials can inject arbitrary operating system commands through improperly sanitized media definitions, potentially gaining elevated system privileges and compromising the underlying infrastructure.

Technical details

The vulnerability is an OS command injection flaw (CWE-78) in the media definition handling of WeOS 5.24 and later. The root cause is unsafe processing of special characters in media definitions that fails to properly neutralize shell metacharacters before command execution. Exploitation requires authenticated administrator access and user interaction, making the attack complexity high. A successful exploit grants the attacker the ability to execute arbitrary commands with privileges beyond those normally available, potentially achieving full system compromise. Patches are expected from Westermo; in the interim, administrative access controls and network segmentation are the primary mitigations.

Affected products

  • Westermo Network Technologies WeOS 5 5.24 and later

Timeline

  • 2025-09-18: disclosed: CISA advisory ICSA-25-261-01 published

References