PT-2025-26590 · Materialise · Materialise Orthoview
Joe Dillon
·
Published
2025-06-23
·
Updated
2026-01-28
·
CVE-2025-23049
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
Meridian Technique Materialise OrthoView versions through 7.5.1
Description
Meridian Technique Materialise OrthoView through version 7.5.1 is susceptible to an OS Command Injection when servlet sharing is enabled. This allows for potential remote code execution and authentication bypass. The issue occurs when the application improperly handles user-supplied input, allowing attackers to inject arbitrary commands that are then executed by the operating system. The vulnerable component is related to servlet sharing functionality.
Recommendations
Versions prior to 7.5.1 should be updated.
Disable servlet sharing functionality to mitigate the risk.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Materialise Orthoview