PT-2025-39149 · Unknown+1 · Clevercontrol+1

CVE-2025-10548

·

Publicado

2025-09-23

·

Atualizado

2025-09-26

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions CleverControl versions prior to 11.5.1041.6
Description The software does not validate TLS server certificates during installation. The installer uses curl.exe --insecure to download and execute external components, allowing a man-in-the-middle attacker to deliver malicious files. These files are executed with SYSTEM privileges, potentially leading to full remote code execution with administrative rights.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-10548

Produtos afetados

Clevercontrol
Curl