VORANT. Threat Intelligence Sign in Get the full feed

NEC CLUSTERPRO X flaw allows unauthenticated RCE

high vulnerability technology

A critical OS command injection flaw in NEC's CLUSTERPRO X/EXPRESSCLUSTER X clustering software lets attackers run arbitrary commands via crafted network packets without authentication.

IPA and JVN published an advisory for CVE-2025-11546, an OS command injection vulnerability affecting NEC's CLUSTERPRO X and EXPRESSCLUSTER X clustering software for Linux. The flaw carries a CVSS v3 score of 9.8 and allows a remote attacker to execute arbitrary OS commands without authentication by sending specially crafted network packets to the affected product.

The vulnerability affects a wide range of versions across both product lines, from 4.0 through 5.2, including the SingleServerSafe variants. Given that clustering software is typically deployed in high-availability enterprise environments to manage failover for critical business systems, successful exploitation could lead to full compromise of underlying infrastructure supporting mission-critical applications.

NEC has released updated versions and workarounds to mitigate the issue. IPA recommends affected organizations update to the latest version or apply the vendor-provided workaround immediately, and to consult NEC directly for further technical details. No evidence of active exploitation was reported in the advisory.

Mentioned in this report

Vulnerabilities CVE-2025-11546

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20251107-jvn.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free