CVE-2025-4740

MEDIUM

BeamCtrl Airiana <11.0 - Deserialization

Title source: llm
STIX 2.1

Description

A vulnerability was found in BeamCtrl Airiana up to 11.0. It has been declared as problematic. This vulnerability affects unknown code of the file coef. The manipulation leads to deserialization. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.309040
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.309040
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.570888
Issue Tracking issue-tracking
https://github.com/BeamCtrl/Airiana/issues/42

Scores

CVSS v3 5.3
EPSS 0.0016
EPSS Percentile 5.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-502
Status published
Products (1)
BeamCtrl/Airiana 11.0
Published May 16, 2025
Tracked Since Feb 18, 2026