Junglewise Threat Intelligence

CVE-2025-69600: Raynet RayVentory Scan Engine command injection in rvia

CVE-2025-69600 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Raynet RayVentory Scan Engine. Vendors: Raynet.

Executive brief

Raynet RayVentory Scan Engine is a tool used for IT asset discovery and inventory management. A security vulnerability in its scanning component allows a local attacker to execute unauthorized commands on the system. This could lead to a full system takeover, allowing an attacker to access sensitive inventory data or disrupt IT operations.

Technical details

Raynet RayVentory Scan Engine (rvia) contains multiple command injection vulnerabilities in its command-line interface. The application fails to properly sanitize or terminate arguments passed to options such as 'getconfig', 'upload', 'inventory', and 'oracle'. Specifically, an attacker can inject shell commands by using semicolons or other shell metacharacters in these arguments. Additionally, the application is vulnerable to argument injection in its internal search logic; it uses an incorrectly constructed 'find' command to locate Java runtimes, which can be exploited by creating a crafted directory structure that satisfies the malformed search criteria. These flaws allow a local attacker to achieve arbitrary code execution with the privileges of the rvia process.

Affected products

  • Raynet RayVentory Scan Engine (rvia) 12.6 Update 8 and earlier

Timeline

  • 2026-05-27: advisory: NVD publication date

References

Related threats