CVE-2025-64151
Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows
Description
Description
Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Affected Vendors & Products
| Vendor | Product | Version |
|---|---|---|
| roboticsware | fa-panel6 | * |
| roboticsware | fa-server6 | * |
| roboticsware | ba-panel6 | * |
| roboticsware | pa-panel6 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-428 | The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
How can this vulnerability impact me? :
How can this vulnerability be detected on my network or system? Can you suggest some commands?
What immediate steps should I take to mitigate this vulnerability?
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart
Meta Information
CVE Publication Date:
2025-11-05
CVE Last Modified Date:
2025-11-05
Report Generation Date:
2025-11-06
AI Powered Q&A Generation:
2025-11-05
EPSS Last Evaluated Date:
2025-11-05
NVD Report Link: