CVE-2025-64348

Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
31/10/2025
Last modified:
10/11/2025

Description

ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the execute facility is specifically enabled with the "-x" command line flag, attackers could execute OS commands on the host machine. By default, ELOG is not configured to allow shell commands or self-registration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elog_project:elog:*:*:*:*:*:*:*:* 3.1.5-20251014 (including)