CVE-2025-3686

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 16, 2025
CWE ID 22

Summary

CVE-2025-3686 is a newly disclosed vulnerability affecting the misstt123 oasys 1.0 software. The issue lies within the 'image' function of the '/show' file, which enables path traversal, allowing attackers to manipulate the system's file paths. This vulnerability can be exploited remotely, giving attackers unauthorized access to sensitive data or even system takeover. Regrettably, the public now has access to the exploit, making it essential for users of misstt123 oasys 1.0 to apply a patch or upgrade as soon as possible. Unfortunately, version information for this product is not available, making it difficult to determine which releases are affected or unaffected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Omgeo OASYS

Affected Vendors

  • Depository Trust & Clearing