CVE-2025-3621
CRITICALActADUR <2.0.2.0 - Command Injection
Title source: llmDescription
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems. * vulnerabilities: * Improper Neutralization of Special Elements used in a Command ('Command Injection') * Use of Hard-coded Credentials * Improper Authentication * Binding to an Unrestricted IP Address The vulnerability has been rated as critical.This issue affects ActADUR: from v2.0.1.9 before v2.0.2.0., hence updating to version v2.0.2.0. or above is required.
References (1)
Scores
CVSS v3
9.6
EPSS
0.0031
EPSS Percentile
53.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Classification
CWE
CWE-287
CWE-798
CWE-1327
CWE-77
Status
draft
Timeline
Published
Jul 15, 2025
Tracked Since
Feb 18, 2026