WaveStore Server software was found to contain several high-severity vulnerabilities related to improper path validation in scripts accessible via the WaveView client. Attackers with high privileges could exploit these flaws to execute arbitrary operating system commands or read and delete files on the server. Specifically, CVE-2025-65074 allows OS command injection through path traversal in the showerr script, while CVE-2025-65076 enables arbitrary file read and deletion via the ilog script, which runs with root privileges. All vulnerabilities affect versions prior to 6.44.44, and have been addressed in that release.
CERT Polska coordinated the disclosure of these vulnerabilities, which stem from the WaveView client’s ability to execute a restricted set of predefined commands and scripts on the connected server. The vulnerabilities are classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory), and pose significant risks if exploited, including full compromise of server confidentiality and integrity. Organizations using WaveStore Server are strongly advised to update to version 6.44.44 or later to mitigate these threats.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
CERT Polska publicly disclosed the three critical WaveStore Server vulnerabilities, including CVE-2025-65074 and CVE-2025-65076, and advised updating affected systems. The disclosure stated that all versions before 6.44.44 were vulnerable.
The vendor remediated the three vulnerabilities in WaveStore Server version 6.44.44. The update addressed command execution and file read/delete issues, including one flaw that could access or delete files with root privileges.
Three critical path traversal vulnerabilities in WaveStore Server, later assigned CVE-2025-65074, CVE-2025-65075, and CVE-2025-65076, were responsibly reported to CERT Polska. The flaws affected all versions prior to 6.44.44 and enabled command execution or file read/delete via the WaveView client.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecert.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.