CVE-2025-31713
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.4epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
In short
A hidden service in engineer mode allows attackers to inject malicious commands through improperly validated input, giving them higher privileges on the system without needing special access first.
Technical detail
The engineer mode service fails to properly sanitize user-supplied input, enabling OS command injection that bypasses privilege boundaries. An unauthenticated or low-privileged local attacker can execute arbitrary commands with elevated privileges, achieving local privilege escalation without requiring pre-existing elevated permissions.
Summary generated and translated by AI from the official description.
In engineer mode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H