CVE-2025-25598

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Mar 13, 2025
Updated: Apr 3, 2025
CWE ID 284

Summary

CVE-2025-25598 is a newly discovered vulnerability affecting the Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1. This issue stems from an incorrect access control in the scheduled tasks console. Malicious actors can exploit this flaw by placing a specially crafted executable into a scheduled task, thereby escalating their privileges. This vulnerability poses a significant risk, as it allows attackers to gain unauthorized access to sensitive customer data and potentially disrupt system operations. Organizations using this product are urged to patch immediately to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share