CVE-2025-31932

HIGH

BizRobo! - Code Injection

Title source: llm

Description

Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.

Scores

CVSS v3 8.8
EPSS 0.0041
EPSS Percentile 61.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status draft

Timeline

Published Apr 11, 2025
Tracked Since Feb 18, 2026