Executive brief
A security vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server, a device used to provide precise timing and synchronization for corporate and industrial networks. An attacker could trick a logged-in user into performing unintended actions on the device's management interface. If successful, this could allow the attacker to change system settings, disrupt time synchronization services, or gain unauthorized access to sensitive network information.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware 6010-0071-000 Ver 4.00. The application fails to implement sufficient anti-CSRF tokens or validation for state-changing requests. An attacker can exploit this by inducing an authenticated user to visit a malicious website or click a crafted link, allowing the attacker to execute unauthorized actions with the victim's privileges. This can lead to arbitrary code execution, privilege escalation, or a denial-of-service (DoS) condition. As of the advisory date, a formal patch has not been released, but the vendor recommends disabling the web management interface (HTTPD) as a mitigation.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA - Cyber Security.
- 2025-10-03: advisory: Security advisory published by researchers.
- 2025-10-06: other: CVE records published.