Executive brief
EndRun Technologies Sonoma D12 is a network time server used to provide precise GPS-based synchronization for corporate and industrial networks. A security flaw allows an attacker to inject malicious commands into the device's operating system. If exploited, this could lead to unauthorized code execution, service disruptions, or full control over the time-keeping infrastructure.
Technical details
An OS command injection vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware 6010-0071-000 Ver 4.00. The flaw stems from improper neutralization of special elements used in OS commands (CWE-78), likely within the web management interface. While the NVD summary suggests unauthenticated access, the researcher advisory classifies this specific CVE as requiring high privileges (PR:H) for remote code execution. Successful exploitation allows an attacker to execute arbitrary system commands, potentially leading to privilege escalation and full system compromise. As a workaround, the vendor recommends disabling the web management service (httpd) until a formal patch is released.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA PT Team
- 2025-10-03: advisory: Security advisory published by researchers
- 2025-10-06: other: CVE records published on CVE.org