CVE-2025-31715
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 1.5%
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in vowifi service allows attackers to inject malicious commands through improperly validated user input, potentially gaining unauthorized elevated privileges on the system.
Technical detail
Remote command injection vulnerability in vowifi service stemming from insufficient input validation. Attackers can exploit this via network access without requiring prior privileges, achieving arbitrary code execution and privilege escalation on the affected system.
Summary generated and translated by AI from the official description.
In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H