THREAT OPS › Threat News › [NVD] CVE-2025-34115 — An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as th
[NVD] CVE-2025-34115 — An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as th
CVE-2025-34115 CVSS: None Published: 2025-07-15T13:15:31.437
An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user. The vulnerability re
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2025-34115cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-34115