PT-2025-10599 · Visicut · Visicut

Roy Blume

·

Published

2025-03-10

·

Updated

2025-06-23

·

CVE-2025-25940

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VisiCut version 2.1
Description The issue allows code execution via insecure XML deserialization in the loadPlfFile method of VisicutModel.java.
Recommendations For VisiCut version 2.1, consider restricting the use of the loadPlfFile method in VisicutModel.java until a patch is available.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-25940

Affected Products

Visicut