Executive brief
The EndRun Technologies Sonoma D12 is a network time server used to provide precise GPS-based synchronization for corporate and industrial networks. A security flaw allows an attacker with low-level access to take complete control of the device. This could lead to the disruption of time-sensitive operations, theft of sensitive configuration data, or the use of the device as a foothold to attack other parts of the internal network.
Technical details
An OS command injection vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware version 6010-0071-000 v4.00. The flaw likely stems from the use of unsafe functions like system() or popen() without proper input sanitization in the web management interface. A remote attacker with low-privileged credentials can exploit this to execute arbitrary shell commands with elevated privileges. This can result in a total compromise of the device (Remote Code Execution), denial of service, or unauthorized access to sensitive system files. As of the advisory date, a formal patch is pending, but the vendor recommends disabling the web management interface as a workaround.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA Cyber Security.
- 2025-10-03: advisory: Public advisory released by researchers.
- 2025-10-06: other: CVE published.