CVE-2025-3621
Severity CVSS v4.0:
CRITICAL
Type:
CWE-77
Command Injection
Publication date:
15/07/2025
Last modified:
15/07/2025
Description
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. <br />
<br />
<br />
* vulnerabilities:<br />
* <br />
<br />
Improper Neutralization of Special Elements used in a Command (&#39;Command Injection&#39;)<br />
* Use of Hard-coded Credentials<br />
* Improper Authentication<br />
* Binding to an Unrestricted IP Address<br />
<br />
<br />
<br />
The vulnerability has been rated as critical.This issue affects ActADUR: from v2.0.1.9 before v2.0.2.0., hence updating to version v2.0.2.0. or above is required.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL
Base Score 3.x
9.60
Severity 3.x
CRITICAL



