Junglewise Threat Intelligence

CVE-2025-60965: EndRun Technologies Sonoma D12 OS command injection

CVE-2025-60965 · Severity: critical · CVSS 9.1 · Published 2025-10-06

Technologies: EndRun Technologies Sonoma D12 Network Time Server, Endruntechnologies Sonoma D12, Endruntechnologies Sonoma D12 Firmware. Vendors: EndRun Technologies, Endruntechnologies.

Executive brief

EndRun Technologies Sonoma D12 is a network time server used to provide precise GPS-based synchronization for corporate and industrial networks. A security vulnerability allows an attacker with administrative access to take full control of the device by injecting malicious commands. This could lead to a complete service outage, theft of sensitive configuration data, or the device being used as a foothold to attack other parts of the network.

Technical details

An OS command injection vulnerability exists in the EndRun Technologies Sonoma D12 Network Time Server (GPS) running firmware version 6010-0071-000 v4.00. The flaw stems from improper neutralization of special elements used in OS commands, likely due to the use of unsafe functions like system() or popen() within the web management interface. An attacker with high-privileged credentials can exploit this over the network to execute arbitrary code with elevated privileges, potentially leading to a full system compromise or denial-of-service. While a formal firmware patch is pending, the vendor recommends disabling the web management interface (HTTPD) as a temporary mitigation.

Affected products

  • EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00

Timeline

  • 2025-08-31: disclosed: Vulnerabilities discovered and reported to vendor by SDAIA PT Team.
  • 2025-10-03: advisory: Security advisory published by researchers.
  • 2025-10-06: other: CVE records published.

References

Related threats