Junglewise Threat Intelligence

CVE-2025-60964: EndRun Technologies Sonoma D12 OS command injection

CVE-2025-60964 · Severity: critical · CVSS 9.1 · Published 2025-10-06

Technologies: EndRun Technologies Sonoma D12 Network Time Server, Endruntechnologies Sonoma D12, Endruntechnologies Sonoma D12 Firmware. Vendors: EndRun Technologies, Endruntechnologies.

Executive brief

The EndRun Technologies Sonoma D12 is a network time server used to provide precise GPS-based synchronization for corporate and industrial networks. A security vulnerability in its management interface allows an attacker with administrative access to execute unauthorized commands on the underlying operating system. This could lead to a total takeover of the device, allowing an attacker to disrupt network timing services, steal sensitive configuration data, or use the server as a foothold to attack other parts of the network.

Technical details

An OS command injection vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware version 6010-0071-000 Ver 4.00. The flaw is rooted in the improper neutralization of special elements used in OS commands (CWE-78), likely within the web management interface. An attacker with high-privileged (administrative) credentials can exploit this via the network to execute arbitrary commands with the privileges of the web service. Successful exploitation can lead to remote code execution (RCE), privilege escalation to root, and persistent system compromise. While a formal patch is not yet specified, the vendor recommends disabling the web management interface as a mitigation.

Affected products

  • EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00

Timeline

  • 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA - Cyber Security
  • 2025-10-03: advisory: Security advisory published by researchers
  • 2025-10-06: other: CVE records published on CVE.org

References

Related threats