CVE-2025-62002

MEDIUM

BullWall Ransomware Containment <4.6.1.4 - Authenticated RCE

Title source: llm
STIX 2.1

Description

BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection if thresholds are configured to require multiple file changes. The number of files to trigger detection can be configured by the user. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

References (2)

Core 2
Core References
Third Party Advisory vdb-entry
https://www.cve.org/CVERecord?id=CVE-2025-62002

Scores

CVSS v3 4.3
EPSS 0.0026
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-358
Status published
Products (4)
bullwall/ransomware_containment 4.6.0.0
bullwall/ransomware_containment 4.6.0.6
bullwall/ransomware_containment 4.6.0.7
bullwall/ransomware_containment 4.6.1.4
Published Dec 18, 2025
Tracked Since Feb 18, 2026