CVE-2025-3411

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 918

Summary

CVE-2025-3411 is a critical server-side request forgery vulnerability that has been identified in the mymagicpower AIAS 20250308 system. This issue lies in the processing of the file 3_api_platform/api-platform/src/main/java/top/aias/platform/controller/AsrController.java. Maliciously crafted URL arguments can be manipulated to trigger unintended server-side requests. The attack can be initiated remotely, and the exploit has already been disclosed to the public. Despite early notification, the vendor has not responded to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share