CVE-2025-0471

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 434

Summary

CVE-2025-0471 is an unrestricted file upload vulnerability discovered in the PMB platform, affecting versions 4.0.10 and later. An attacker can exploit this flaw to upload a malicious file, potentially gaining unauthorized remote access to the targeted machine. Once accessed, the attacker can freely modify and execute commands, posing a significant risk to the security of the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share