CVE-2025-46070
Unknown Unknown - Not Provided
Remote Code Execution in Automai BotManager BotManager.exe

Publication date: 2026-01-12

Last updated on: 2026-01-12

Assigner: MITRE

Description
An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-12
Last Modified
2026-01-12
Generated
2026-05-07
AI Q&A
2026-01-13
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
automai botmanager 25.2.0
automai botmanager to 25.2.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability allows remote attackers to execute arbitrary code, potentially leading to unauthorized access, data manipulation, or exfiltration. Such impacts can compromise confidentiality, integrity, and availability of sensitive data, which may result in non-compliance with standards and regulations like GDPR and HIPAA that require protection of personal and healthcare information. Therefore, exploitation of this vulnerability could negatively affect compliance with these regulations by exposing sensitive data and undermining system security. [1]


Can you explain this vulnerability to me?

CVE-2025-46070 is a critical command injection vulnerability in Automai BotManager versions prior to 25.2.0. It is caused by improper or missing certificate validation, allowing a remote attacker to execute arbitrary system commands with the application's privileges by presenting a crafted certificate or intercepting the connection. The vulnerability requires no privileges or user interaction and has a high impact on confidentiality, integrity, and availability. [1]


How can this vulnerability impact me? :

Exploitation of this vulnerability can lead to unauthorized access, data manipulation or exfiltration, malware installation, and potentially full system and infrastructure compromise, severely impacting confidentiality, integrity, and availability of affected systems. [1]


How can this vulnerability be detected on my network or system? Can you suggest some commands?

Detection of CVE-2025-46070 involves monitoring for unusual or unauthorized command executions related to the BotManager.exe component, especially attempts to exploit command injection via crafted certificates or intercepted connections. Specific detection commands or scripts are not provided in the available resources. [1]


What immediate steps should I take to mitigate this vulnerability?

Immediate mitigation steps include applying the vendor's fix released in May 2025 for Automai BotManager versions prior to 25.2.0. Additionally, ensure proper certificate validation is enforced to prevent command injection attacks, restrict network access to the BotManager.exe component, and monitor for suspicious activity related to this vulnerability. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart