A critical vulnerability, CVE-2025-4009, has been identified in Evertz SDVN 3080ipx-10G and other devices leveraging the webEASY (ewb) management interface. This flaw affects all current versions and arises from a combination of an authentication bypass and unauthenticated command injection in administrative endpoints. By crafting a specially encoded JSON token, attackers can gain unauthorized administrative access. Leveraging this access, they can exploit the feature-transfer-import.php and feature-transfer-export.php endpoints to inject arbitrary system commands. This vulnerability enables unauthenticated remote code execution (RCE) as root on affected devices, potentially allowing full system takeover, disruption of broadcast workflows, and lateral movement within media infrastructure networks. The IONIX research team validated the impact through successful exploit reproduction, as detailed in this advisory.
References:

