Executive brief
EndRun Technologies Sonoma D12 is a network time server used to provide precise GPS-synchronized timing to corporate and industrial networks. A security flaw allows an attacker to inject malicious commands into the device's operating system. If exploited, this could allow an attacker to gain unauthorized access to sensitive information, disrupt time-synchronization services, or potentially take full control of the device.
Technical details
An OS command injection vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware 6010-0071-000 Ver 4.00. The flaw stems from improper neutralization of special elements used in OS commands (CWE-78), likely due to the use of unsafe functions like system() or popen() within the web management interface. While the CISA-ADP CVSS score suggests a high-privilege requirement for some related RCEs, this specific CVE is noted for allowing attackers to gain sensitive information. A vendor-confirmed workaround involves disabling the web management service (httpd) via command-line configuration changes until a formal patch is released.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA Cyber Security.
- 2025-10-03: advisory: Security advisory published by researchers.
- 2025-10-06: other: CVE records published.