← back
CVE-2025-30055criticalCWE-94

Conditional RCE via the "system" function

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code provided as the "Module" parameter.
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
CGM · CGM CLININET