CVE-2025-0455
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-0455 is a newly identified SQL Injection vulnerability affecting the airPASS system from NetVision Information. This issue enables unauthenticated attackers to inject malicious SQL commands directly into the system, granting them unauthorized access to modify or delete sensitive database data. The vulnerability poses a significant risk, as it can be exploited remotely without the need for valid credentials. Successful exploitation could lead to data theft, unauthorized system changes, or even complete system compromise. It is strongly recommended that users of the airPASS system apply the necessary patches or upgrades as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.