PT-2025-23474 · Diviotec · Diviotec Professional Series

Quentin Kaiser

·

Published

2025-06-02

·

Updated

2025-06-04

·

CVE-2025-5113

CVSS v4.0

8.6

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The Diviotec professional series (affected versions not specified)
Description The issue concerns the exposure of a web interface in the Diviotec professional series, where one endpoint is vulnerable to arbitrary command injection. Additionally, hardcoded passwords are used, which poses a security risk.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-5113

Affected Products

Diviotec Professional Series