CVE-2025-43946
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 22, 2025
Updated: Apr 25, 2025
CWE ID 434
Summary
CVE-2025-43946 is a remote code execution vulnerability affecting TCPWave DDI version 11.34P1C2. An attacker can exploit this issue by uploading an unrestricted file and performing a path traversal attack. As a result, the server will execute the attacker's code, potentially leading to unauthorized system access and data theft or manipulation. This vulnerability poses a serious threat to organizations using the TCPWave DDI software and requires immediate patching to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- ddI