CVE-2025-31932

HIGH

BizRobo! - Remote Code Execution via Untrusted Data Deserialization

Title source: llm
STIX 2.1

Description

Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.

Scores

CVSS v3 8.8
EPSS 0.0057
EPSS Percentile 42.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
OPEN, Inc./BizRobo! all versions
Published Apr 11, 2025
Tracked Since Feb 18, 2026