PT-2025-33502 · Msoft · Msoft Mflash
Marsel Shagiev
·
Published
2025-08-15
·
Updated
2025-08-16
·
CVE-2025-9060
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
MSoft MFlash version 8.0
Description:
A vulnerability has been found in MSoft MFlash that allows execution of arbitrary code on the server. The issue occurs in the integration configuration functionality, which is only available to administrators. The vulnerability is related to insufficient validation of parameters when setting up security components.
Recommendations:
Apply MSoft MFlash 8.2-653 hotfix 11.06.2025 and above.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Msoft Mflash