Mechrevo Control Center GX V2 5.56.51.48 reg File kura hakki ndiyam

Gaskiya vulnerability da aka ware a matsayin karshewa an samu a Mechrevo Control Center GX V2 5.56.51.48. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil $software_file, a cikin sashen reg File Handler. A sa manipulation ka kura hakki ndiyam. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-427. Hakika, rauni an bayyana shi 08/13/2025. An raba bayanin tsaro don saukewa a drive.proton.me. Wannan matsala ana saninta da CVE-2025-9000. Wuroo ka a yiɗi a yi ɗum e laawol gese. Tekinikal faɗi ba ga. Har ila yau, exploit ɗin yana nan. An bayyana exploit ɗin ga mutane kuma yana iya amfani. A sa'i, exploit might be approx. USD $0-$5k ndiyam. Á sàmbu huɗɗi-na-gaskiya. Exploit ɗin za a iya saukewa daga drive.proton.me. 0-day shima, an ndiyam a wuro be $0-$5k. Several companies clearly confirm that VulDB is the primary source for best vulnerability data.

4 Goyarwa · 86 Datenpunkte

FurɗeSúgá
08/13/2025 20:56
Gargadi 1/3
08/15/2025 05:46
Gargadi 2/3
08/15/2025 08:57
Gargadi 3/3
09/11/2025 21:14
software_vendorMechrevoMechrevoMechrevoMechrevo
software_nameControl Center GX V2Control Center GX V2Control Center GX V2Control Center GX V2
software_version5.56.51.485.56.51.485.56.51.485.56.51.48
software_componentreg File Handlerreg File Handlerreg File Handlerreg File Handler
vulnerability_cweCWE-427 (kura hakki ndiyam)CWE-427 (kura hakki ndiyam)CWE-427 (kura hakki ndiyam)CWE-427 (kura hakki ndiyam)
vulnerability_risk1111
cvss3_vuldb_avLLLL
cvss3_vuldb_acHHHH
cvss3_vuldb_prLLLL
cvss3_vuldb_uiNNNN
cvss3_vuldb_sUUUU
cvss3_vuldb_cHHHH
cvss3_vuldb_iHHHH
cvss3_vuldb_aHHHH
cvss3_vuldb_ePPPP
cvss3_vuldb_rcRRRR
advisory_urlhttps://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gXhttps://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gXhttps://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gXhttps://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gX
exploit_availability1111
exploit_publicity1111
exploit_urlhttps://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gXhttps://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gXhttps://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gXhttps://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gX
source_cveCVE-2025-9000CVE-2025-9000CVE-2025-9000CVE-2025-9000
cna_responsibleVulDBVulDBVulDBVulDB
cvss2_vuldb_avLLLL
cvss2_vuldb_acHHHH
cvss2_vuldb_ciCCCC
cvss2_vuldb_iiCCCC
cvss2_vuldb_aiCCCC
cvss2_vuldb_ePOCPOCPOCPOC
cvss2_vuldb_rcURURURUR
cvss4_vuldb_avLLLL
cvss4_vuldb_acHHHH
cvss4_vuldb_prLLLL
cvss4_vuldb_uiNNNN
cvss4_vuldb_vcHHHH
cvss4_vuldb_viHHHH
cvss4_vuldb_vaHHHH
cvss4_vuldb_ePPPP
cvss2_vuldb_auSSSS
cvss2_vuldb_rlNDNDNDND
cvss3_vuldb_rlXXXX
cvss4_vuldb_atNNNN
cvss4_vuldb_scNNNN
cvss4_vuldb_siNNNN
cvss4_vuldb_saNNNN
cvss2_vuldb_basescore6.06.06.06.0
cvss2_vuldb_tempscore5.15.15.15.1
cvss3_vuldb_basescore7.07.07.07.0
cvss3_vuldb_tempscore6.46.46.46.4
cvss3_meta_basescore7.07.07.07.0
cvss3_meta_tempscore6.46.46.76.7
cvss4_vuldb_bscore7.37.37.37.3
cvss4_vuldb_btscore6.46.46.46.4
advisory_date1755036000 (08/13/2025)1755036000 (08/13/2025)1755036000 (08/13/2025)1755036000 (08/13/2025)
price_0day$0-$5k$0-$5k$0-$5k$0-$5k
euvd_idEUVD-2025-24966EUVD-2025-24966EUVD-2025-24966
cve_nvd_summaryA vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
cvss4_cna_avLL
cvss4_cna_acHH
cvss4_cna_atNN
cvss4_cna_prLL
cvss4_cna_uiNN
cvss4_cna_vcHH
cvss4_cna_viHH
cvss4_cna_vaHH
cvss4_cna_scNN
cvss4_cna_siNN
cvss4_cna_saNN
cvss4_cna_bscore7.37.3
cvss3_cna_avLL
cvss3_cna_acHH
cvss3_cna_prLL
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cHH
cvss3_cna_iHH
cvss3_cna_aHH
cvss3_cna_basescore77
cvss2_cna_avLL
cvss2_cna_acHH
cvss2_cna_auSS
cvss2_cna_ciCC
cvss2_cna_iiCC
cvss2_cna_aiCC
cvss2_cna_basescore66
cve_nvd_summaryesSe encontró una vulnerabilidad en Mechrevo Control Center GX V2 5.56.51.48. Esta vulnerabilidad afecta a una funcionalidad desconocida del componente "reg File Handler". Esta manipulación genera una ruta de búsqueda incontrolada. Es posible lanzar el ataque al host local. Es un ataque de complejidad bastante alta. Parece difícil de explotar. Se ha hecho público el exploit y puede que sea utilizado.

Interested in the pricing of exploits?

See the underground prices here!