PT-2025-22398 · Unknown · Ackites Killwxapkg

Zznq

·

Published

2025-05-21

·

Updated

2025-08-04

·

CVE-2025-5030

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ackites KillWxapkg versions up to 2.4.1
Description A critical issue affects the processFile function of the wxapkg File Parser component, located in the file internal/unpack/unpack.go. This issue leads to os command injection and can be initiated remotely. The complexity of an attack is rather high, and the exploitation appears to be difficult.
Recommendations For Ackites KillWxapkg versions up to 2.4.1, as a temporary workaround, consider disabling the processFile function until a patch is available. Restrict access to the wxapkg File Parser component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5030
GHSA-W6P4-84VC-QC2W
GO-2025-3773
OPENSUSE-SU-2025:15405-1

Affected Products

Ackites Killwxapkg