CVE-2025-62002

MEDIUM

BullWall Ransomware Containment <4.6.1.4 - Authenticated RCE

Title source: llm
STIX 2.1

Description

BullWall Ransomware Containment considers the number of files modified to trigger detection. An authenticated attacker could encrypt a single (possibly large) file without triggering detection if thresholds are configured to require multiple file changes. The number of files to trigger detection can be configured by the user. Versions 4.6.0.0, 4.6.0.6, 4.6.0.7, and 4.6.1.4 are affected. Other versions may also be affected.

Scores

CVSS v3 4.3
EPSS 0.0002
EPSS Percentile 5.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-358
Status published
Products (4)
bullwall/ransomware_containment 4.6.0.0
bullwall/ransomware_containment 4.6.0.6
bullwall/ransomware_containment 4.6.0.7
bullwall/ransomware_containment 4.6.1.4
Published Dec 18, 2025
Tracked Since Feb 18, 2026