CVE-2025-31932
HIGHBizRobo! - Code Injection
Title source: llmDescription
Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.
References (5)
Scores
CVSS v3
8.8
EPSS
0.0041
EPSS Percentile
61.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
draft
Timeline
Published
Apr 11, 2025
Tracked Since
Feb 18, 2026