CVE-2025-9060
MFlash Remote Code Execution (RCE) after authentication of a user with the "administrator" role
A vulnerability has been found in the MSoft MFlash
application that allows
execution of arbitrary code on the server. The issue occurs in the
integration configuration functionality that is only available to
MFlash
administrators. The vulnerability is related to insufficient validation
of parameters when setting up security components.
This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Productos afectados
MSoft · MFlash¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →