PT-2025-30318 · Unknown · Eveo Urve Web Manager

Stefan Krause

·

Published

2025-07-21

·

Updated

2025-09-12

·

CVE-2025-36846

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eveo URVE Web Manager version 27.02.2025
Description The application exposes the / internal/pc/vpro.php endpoint to unauthenticated users, which is vulnerable to OS Command Injection. The endpoint accepts an input parameter that is directly passed into the shell exec() function of PHP.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-36846

Affected Products

Eveo Urve Web Manager