The TLS4B ATG system's SOAP-based interface is vulnerable...
        
  Critical severity
        
          Unreviewed
      
        Published
          Oct 23, 2025 
          to the GitHub Advisory Database
          •
          Updated Oct 23, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Oct 23, 2025 
    
  
        Published to the GitHub Advisory Database
      Oct 23, 2025 
    
  
        Last updated
      Oct 23, 2025 
    
  
The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. This vulnerability enables remote attackers with valid credentials to execute system-level commands on the underlying Linux system. This could allow the attacker to achieve remote command execution, full shell access, and potential lateral movement within the network.
References