CVE-2025-31710
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
In short
The engineermode service fails to properly validate user input, allowing attackers to inject commands that execute with elevated privileges. This could let an attacker take control of the system locally without needing special permissions first.
Technical detail
CWE-77 command injection vulnerability in the engineermode service due to insufficient input validation. Local attacker can inject arbitrary commands through unvalidated parameters, leading to privilege escalation without requiring pre-existing elevated privileges or additional execution context.
Summary generated and translated by AI from the official description.
In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L