CVE-2025-23239 — When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit — CVE Database · The Intelligence Room