CVE-2025-33181

HIGH WAF: High
CVSS 8.8 Published: 2026-02-24
CWE-77

NVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A successful exploit of this vulnerability might lead to escalation of privileges.

WAF Coverage Analysis

Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
nvidiacumulus_linuxup to 5.14.0
nvidiacumulus_linux5.9.0 - 5.9.4
nvidiacumulus_linux5.11.0 - 5.11.4
nvidianvosup to 25.02.2452
nvidianvosup to 25.02.4282
nvidianvosup to 25.02.5030

References

Back to CVE Database