CVE-2025-3413
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Apr 8, 2025
CWE ID 502
CWE ID 20
Summary
CVE-2025-3413 is a critical vulnerability affecting opplus springboot-admin up to version a2d5310f44fd46780a8686456cf2f9001ab8f024. This issue lies within the SysGeneratorController.java file and stems from improper handling of deserialization related to the argument Tables. An attacker can exploit this remotely, and the code for doing so has been made public. Unfortunately, the lack of product versioning makes it difficult to determine which releases are vulnerable or not. Despite early notification, the vendor has not responded to this disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.