PT-2025-15360 · Unknown · Opplus Springboot-Admin

Maple14711

·

Published

2025-04-08

·

Updated

2025-10-16

·

CVE-2025-3413

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: opplus springboot-admin versions up to a2d5310f44fd46780a8686456cf2f9001ab8f024
Description: A critical vulnerability has been found in the function code of the file SysGeneratorController.java. The manipulation of the argument Tables leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning, which is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Recommendations: As a temporary workaround, consider disabling the SysGeneratorController.java file or restricting access to it until a patch is available. Avoid using the Tables argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-3413

Affected Products

Opplus Springboot-Admin