PT-2025-33502 · Msoft · Msoft Mflash

Marsel Shagiev

·

Published

2025-08-15

·

Updated

2025-08-16

·

CVE-2025-9060

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MSoft MFlash version 8.0
Description: A vulnerability has been found in MSoft MFlash that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality, which is only available to administrators. The vulnerability is related to insufficient validation of parameters when setting up security components.
Recommendations: Apply MSoft MFlash 8.2-653 hotfix 11.06.2025 and above.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-9060

Affected Products

Msoft Mflash