Junglewise Threat Intelligence

CVE-2025-60962: EndRun Technologies Sonoma D12 OS command injection

CVE-2025-60962 · Severity: high · CVSS 8.2 · Published 2025-10-06

Technologies: EndRun Technologies Sonoma D12 Network Time Server, Endruntechnologies Sonoma D12, Endruntechnologies Sonoma D12 Firmware. Vendors: EndRun Technologies, Endruntechnologies.

Executive brief

EndRun Technologies Sonoma D12 is a network time server used to provide precise GPS-synchronized timing for corporate and industrial networks. A security vulnerability allows an attacker with administrative access to execute unauthorized commands on the device's operating system. This could lead to a complete takeover of the device, allowing the attacker to manipulate time synchronization data or use the server as a foothold to attack other parts of the network.

Technical details

An OS command injection vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware 6010-0071-000 Ver 4.00. The flaw is rooted in improper neutralization of special elements used in OS commands (CWE-78), likely within the web management interface. An attacker with high-privileged (administrative) credentials can exploit this via the network to execute arbitrary commands with the privileges of the web service. Successful exploitation can lead to remote code execution (RCE), privilege escalation, and full system compromise. While a formal patch is not explicitly detailed, the vendor recommends disabling the web management interface as a workaround.

Affected products

  • EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00

Timeline

  • 2025-08-31: disclosed: Vulnerabilities reported to vendor by SDAIA - Cyber Security
  • 2025-10-03: advisory: Security advisory published by researchers
  • 2025-10-06: other: CVE records published

References

Related threats