CVE-2025-54762
BaseFortify
Publication date: 2025-08-28
Last updated on: 2025-08-29
Assigner: JPCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dos | ss1 | 16.0.0.10 |
| dos | ss1_cloud | 2.1.3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in SS1 version 16.0.0.10 and earlier (including Media version 16.0.0a and earlier). It allows a remote attacker who is not authenticated to upload arbitrary files to the system and execute operating system commands with SYSTEM-level privileges.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain full control over the affected system by executing commands with SYSTEM privileges remotely without authentication. This can lead to unauthorized access, data theft, system compromise, and potentially complete takeover of the affected environment.