CVE-2025-2566
Severity CVSS v4.0:
CRITICAL
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
24/06/2025
Last modified:
26/06/2025
Description
Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the server.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL