CVE-2025-26924
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 15, 2025
CWE ID 94
Summary
CVE-2025-26924 is a Code Injection vulnerability affecting the NotFound Ohio Extra software. The issue stems from improper code generation controls, allowing attackers to inject malicious code into the system. This vulnerability can be exploited from version n/a through 3.4.7 of NotFound Ohio Extra. Successful exploitation could result in significant security risks, including unauthorized system access or data theft. System administrators are advised to update their NotFound Ohio Extra installations to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.