NEC CLUSTERPRO X flaw allows unauthenticated RCE
A critical OS command injection flaw in NEC's CLUSTERPRO X/EXPRESSCLUSTER X clustering software lets attackers run arbitrary commands via crafted network packets without authentication.
IPA and JVN published an advisory for CVE-2025-11546, an OS command injection vulnerability affecting NEC's CLUSTERPRO X and EXPRESSCLUSTER X clustering software for Linux. The flaw carries a CVSS v3 score of 9.8 and allows a remote attacker to execute arbitrary OS commands without authentication by sending specially crafted network packets to the affected product.
The vulnerability affects a wide range of versions across both product lines, from 4.0 through 5.2, including the SingleServerSafe variants. Given that clustering software is typically deployed in high-availability enterprise environments to manage failover for critical business systems, successful exploitation could lead to full compromise of underlying infrastructure supporting mission-critical applications.
NEC has released updated versions and workarounds to mitigate the issue. IPA recommends affected organizations update to the latest version or apply the vendor-provided workaround immediately, and to consult NEC directly for further technical details. No evidence of active exploitation was reported in the advisory.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20251107-jvn.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free