restdone/CVE-2025-57457

restdone/CVE-2025-57457

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter.