CVE-2026-25070 PUBLISHED

XikeStor SKS8310-8X PingTestSet Command Injection

Assigner: VulnCheck
Reserved: 28.01.2026 Published: 07.03.2026 Updated: 07.03.2026

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. Attackers can inject malicious commands through the destIp parameter to achieve remote code execution with root privileges on the network switch.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Anhui Seeker Electronic Technology Co., LTD.
Product XikeStor SKS8310-8X
Versions Default: unknown
  • affected from 0 to 1.04.B07 (incl.)

Credits

  • Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc. finder
  • VulnCheck coordinator

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE