The specific flaw exists within the Tidal music streaming application. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26357.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23397 | Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Tidal music streaming application. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26357. |
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-25-766/ |
|
Tue, 12 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alpsalpine
Alpsalpine ilx-507 Alpsalpine ilx-507 Firmware |
|
| CPEs | cpe:2.3:o:alpine-usa:ilx-507_firmware:6.0.000:*:*:*:*:*:*:* |
cpe:2.3:h:alpsalpine:ilx-507:-:*:*:*:*:*:*:* cpe:2.3:o:alpsalpine:ilx-507_firmware:6.0.000:*:*:*:*:*:*:* |
| Vendors & Products |
Alpine-usa
Alpine-usa ilx-507 Alpine-usa ilx-507 Firmware |
Alpsalpine
Alpsalpine ilx-507 Alpsalpine ilx-507 Firmware |
Thu, 07 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 Aug 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alpine-usa
Alpine-usa ilx-507 Alpine-usa ilx-507 Firmware |
|
| CPEs | cpe:2.3:h:alpine-usa:ilx-507:-:*:*:*:*:*:*:* cpe:2.3:o:alpine-usa:ilx-507_firmware:6.0.000:*:*:*:*:*:*:* |
|
| Vendors & Products |
Alpine-usa
Alpine-usa ilx-507 Alpine-usa ilx-507 Firmware |
Fri, 01 Aug 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Tidal music streaming application. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-26357. | |
| Title | Alpine iLX-507 Command Injection Remote Code Execution | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2025-08-07T16:06:00.334Z
Reserved: 2025-08-01T17:32:13.995Z
Link: CVE-2025-8480
Updated: 2025-08-01T18:45:56.233Z
Status : Analyzed
Published: 2025-08-01T18:15:58.333
Modified: 2025-08-12T18:10:14.043
Link: CVE-2025-8480
No data.
OpenCVE Enrichment
No data.
EUVD