PT-2025-15360 · Unknown · Opplus Springboot-Admin
Maple14711
·
Published
2025-04-08
·
Updated
2025-10-16
·
CVE-2025-3413
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
opplus springboot-admin versions up to a2d5310f44fd46780a8686456cf2f9001ab8f024
Description:
A critical vulnerability has been found in the function code of the file SysGeneratorController.java. The manipulation of the argument
Tables leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning, which is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.Recommendations:
As a temporary workaround, consider disabling the
SysGeneratorController.java file or restricting access to it until a patch is available. Avoid using the Tables argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Opplus Springboot-Admin