A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up security components. This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.
History

Sat, 16 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Msoft
Msoft mflash
Vendors & Products Msoft
Msoft mflash

Fri, 15 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 Aug 2025 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in the  MSoft MFlash application that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality that is only available to MFlash administrators. The vulnerability is related to insufficient validation of parameters when setting up security components. This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.
Title MFlash Remote Code Execution (RCE) after authentication of a user with the "administrator" role
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Kaspersky

Published:

Updated: 2025-08-15T17:51:51.859Z

Reserved: 2025-08-15T11:02:05.206Z

Link: CVE-2025-9060

cve-icon Vulnrichment

Updated: 2025-08-15T17:51:45.475Z

cve-icon NVD

Status : Received

Published: 2025-08-15T17:15:34.887

Modified: 2025-08-15T17:15:34.887

Link: CVE-2025-9060

cve-icon Redhat

No data.