CVE-2025-66461
Severity CVSS v4.0:
HIGH
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
08/12/2025
Last modified:
08/12/2025
Description
FULLBACK Manager Pro provided by GS Yuasa International Ltd. registers two Windows services with unquoted file paths. A user may execute arbitrary code with SYSTEM privilege if he/she has the write permission on the path to the directory where the affected product is installed.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
6.70
Severity 3.x
MEDIUM



