
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-2172 is an OS command injection vulnerability in Aviatrix Controller that allows authenticated attackers to achieve remote code execution by injecting tab characters into uploaded filenames. The flaw affects Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0. It was discovered by Louis Dion-Marcil of Mandiant, reported on March 10, 2025, patched on March 31, 2025, and publicly disclosed on June 23, 2025. The vulnerability carries a CVSS v4.0 base score of 6.6 (Medium) per NVD scoring, though ENISA rates it 7.5 (High) (Mandiant Advisory, ENISA EUVD).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command), classified as OS command injection. Aviatrix Controller allows authenticated users to upload files with arbitrary file extensions, which are saved to disk and subsequently passed to command-line utilities without adequate sanitization. By embedding tab characters in the uploaded file extension, an attacker can bypass Python's shlex argument tokenizer and smuggle unexpected arguments to /usr/bin/cp, ultimately overwriting /etc/crontab to achieve remote code execution. Exploitation requires a high-privileged account (e.g., the "admin" user) and involves installing a certificate with a tampered filename (Mandiant Advisory).
Successful exploitation allows an authenticated attacker to overwrite arbitrary system files — specifically /etc/crontab — leading to full remote code execution on the Aviatrix Controller server. Given that Aviatrix Controller manages cloud network infrastructure, compromise could enable an attacker to pivot into connected cloud environments, intercept or manipulate network traffic, and access sensitive credentials or configuration data. The confidentiality, integrity, and availability of the controller and its managed cloud infrastructure are all at high risk (Mandiant Advisory, Google Cloud Blog).
A proof-of-concept exploit exists, as indicated by the CVSS v4.0 exploit maturity rating of "PROOF_OF_CONCEPT" (Feedly). Exploitation requires a high-privileged account, which limits opportunistic exploitation but does not eliminate risk in environments with compromised admin credentials. The EPSS score is approximately 0.41%, reflecting relatively low automated exploitation probability at this time. No CISA KEV listing or confirmed in-the-wild exploitation has been reported as of the disclosure date, and no specific threat actor attribution has been made (Mandiant Advisory).
shlex argument tokenizer./usr/bin/cp./usr/bin/cp to overwrite /etc/crontab with attacker-controlled content./etc/crontab on the Aviatrix Controller host; presence of newly created files with tab characters in their filenames or extensions in the upload directories./usr/bin/cp with anomalous arguments.curl, wget, bash with network connections); unexpected child processes of the cron daemon.Aviatrix released patches on March 31, 2025; administrators should upgrade to Aviatrix Controller version 7.1.4208, 7.2.5090, or 8.0.0 or later. No configuration-based workaround is documented; upgrading is the recommended remediation. As an interim measure, restrict administrative access to the Aviatrix Controller to trusted IP ranges and enforce multi-factor authentication on admin accounts to reduce the risk of credential compromise that could enable exploitation (Mandiant Advisory).
Mandiant's red team researcher Louis Dion-Marcil publicly disclosed the vulnerability alongside a companion authentication bypass flaw (CVE-2025-2171), with Google Cloud publishing a detailed threat intelligence blog post covering both issues (Google Cloud Blog). Multiple security news outlets including GBHackers, CyberSecurityNews, and The Hacker News covered the disclosure, highlighting the risk to cloud infrastructure managed by Aviatrix Controller (GBHackers, The Hacker News). RunZero also published a blog post on detection and asset identification for affected Aviatrix Controller instances (RunZero). Check Point released an IPS advisory for the vulnerability (Check Point Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."