PT-2025-21874 · Unknown · Iop-Apl-Uw Basestation3
Esharmaji
·
Published
2025-05-19
·
Updated
2025-06-12
·
CVE-2025-4905
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
iop-apl-uw basestation3 versions 3.0.4 and earlier
Description:
A problem was found in the load qc pickl function of the file basestation3/QC.py, which is affected by deserialization due to the manipulation of the
qc file argument. This issue must be approached locally. The exploit has been made public and may be used. Although the code maintainer has tagged the issue as closed, there is no new confirmation or release available in the GitHub repository yet.Recommendations:
For iop-apl-uw basestation3 versions 3.0.4 and earlier, as a temporary workaround, consider disabling the
load qc pickl function until a patch is available. Restrict access to the basestation3/QC.py file to minimize the risk of exploitation. Avoid using the qc file argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iop-Apl-Uw Basestation3