Executive brief
EndRun Technologies Sonoma D12 is a network time server used to provide precise synchronization for corporate and industrial networks. A security flaw allows an attacker to inject malicious commands into the system, potentially leading to full control over the device. This could result in network-wide time synchronization failures, unauthorized access to sensitive configuration data, or the device being used as a foothold for further attacks on the internal network.
Technical details
An OS command injection vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware 6010-0071-000 Ver 4.00. The flaw stems from improper neutralization of special elements in user-supplied input used in OS commands (CWE-78), likely within the web management interface. While some sources indicate high privileges are required, the CISA-ADP assessment suggests a network-based attack vector with no user interaction. Successful exploitation allows for remote code execution (RCE), privilege escalation, and denial-of-service. As a workaround, the vendor recommends disabling the web management service by modifying the startup scripts.
Affected products
- EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00
Timeline
- 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA PT Team.
- 2025-10-03: advisory: Security advisory published by researchers.
- 2025-10-06: other: CVE records published.