#VU121038 Race condition in ShockLine - CVE-2025-15349
Published: January 7, 2026
Vulnerability identifier: #VU121038
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-15349
CWE-ID: CWE-362
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
ShockLine
ShockLine
Software vendor:
Anritsu
Anritsu
Description
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a race condition within the SCPI component. A remote attacker on the local network can exploit the race and execute arbitrary code on the target system.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.