As cited
Copy frozen at (site build).
vulnerabilities
[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)
A command injection vulnerability has been disclosed in OP5 Monitor 9.20 that persists despite the earlier CVE-2025-34115 patch, which was implemented as an optional fix. The new vulnerability carries a CVSS score of 8.8 with high impact on confidentiality, integrity, and availability.
Why it matters: Organizations running OP5 Monitor 9.20 remain at risk of unauthenticated remote code execution if they did not enable the optional mitigation, requiring immediate review of patch deployment and configuration status.
- Source published
- First seen by Cybersecurity Tracker