CVE-2025-3008 | Novastar CX40 up to 2.44.0 NetFilter Utility /usr/nova/bin/netconfig system/popen command injection
A vulnerability classified as critical has been found in Novastar CX40 up to 2.44.0. Affected is the function system/popen of the file /usr/nova/bin/netconfig of the component NetFilter Utility. The manipulation leads to command injection.
This vulnerability is traded as CVE-2025-3008. The attack can only be done within the local network. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.