A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.dragos.com/community/advisories/CVE-2025-64119 |
|
History
Fri, 02 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controller (MSC): through 2.5.1. | A vulnerability in Nuvation Energy nCloud VPN Service allowed Network Boundary Bridging.This issue affected the nCloud VPN Service and was fixed on 2025-12-1 (December, 2025). End users do not have to take any action to mitigate the issue. |
| Title | Nuvation Energy Multi-Stack Controller OS Command Injection | Nuvation Energy nCloud Client-to-Client Communication |
| Weaknesses | CWE-78 | CWE-441 |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 02 Jan 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controller (MSC): through 2.5.1. | |
| Title | Nuvation Energy Multi-Stack Controller OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Dragos
Published:
Updated: 2026-01-02T21:45:30.372Z
Reserved: 2025-10-27T17:12:37.786Z
Link: CVE-2025-64123
No data.
Status : Received
Published: 2026-01-02T22:15:44.787
Modified: 2026-01-02T22:15:44.787
Link: CVE-2025-64123
No data.
OpenCVE Enrichment
No data.