Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-655x-v2mw-gj38

Опубликовано: 15 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 9.6

Описание

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. 

  • vulnerabilities: *

Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • Use of Hard-coded Credentials
  • Improper Authentication
  • Binding to an Unrestricted IP Address

The vulnerability has been rated as critical.This issue affects ActADUR: from v2.0.1.9 before v2.0.2.0., hence updating to version v2.0.2.0. or above is required.

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. 

  • vulnerabilities: *

Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • Use of Hard-coded Credentials
  • Improper Authentication
  • Binding to an Unrestricted IP Address

The vulnerability has been rated as critical.This issue affects ActADUR: from v2.0.1.9 before v2.0.2.0., hence updating to version v2.0.2.0. or above is required.

EPSS

Процентиль: 60%
0.00404
Низкий

9.4 Critical

CVSS4

9.6 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.6
nvd
7 месяцев назад

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.  * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injection') * Use of Hard-coded Credentials * Improper Authentication * Binding to an Unrestricted IP Address The vulnerability has been rated as critical.This issue affects ActADUR: from v2.0.1.9 before v2.0.2.0., hence updating to version v2.0.2.0. or above is required.

EPSS

Процентиль: 60%
0.00404
Низкий

9.4 Critical

CVSS4

9.6 Critical

CVSS3

Дефекты

CWE-77