The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Edimax IC-7100 IP Camera, NAKIVO, and SAP NetWeaver AS Java flaws to its Known Exploited Vulnerabilities catalog.
The vulnerabilities included in the catalog are CVE-2025-1316 Edimax IC-7100 IP Camera OS Command Injection Vulnerability, CVE-2024-48248 NAKIVO Backup and Replication Absolute Path Traversal Vulnerability, and CVE-2017-12637 SAP NetWeaver Directory Traversal Vulnerability.
CVE-2025-1316 refers to an OS command injection vulnerability in Edimax IC-7100 IP cameras that is actively being exploited in the wild.
CISA has ordered federal agencies to address the vulnerabilities by April 9, 2025, and recommends private organizations to review and fix the vulnerabilities in their infrastructure.