PT-2025-38667 · Unknown · Cosmodiumcs Onlyrat

·

CVE-2025-10767

·

Published

2025-09-21

·

Updated

2025-09-24

CVSS v3.1

4.5

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions CosmodiumCS OnlyRAT versions prior to 3.3
Description A vulnerability exists in CosmodiumCS OnlyRAT. The connect/remote upload/remote download function within the main.py file of the Configuration File Handler component is affected. Manipulation of the configuration["PASSWORD"] argument can lead to OS command injection. The attack requires a local approach and is considered difficult to exploit. The exploit is publicly available. The vendor was contacted but did not respond.
Recommendations Versions prior to 3.3: Address the OS command injection issue by sanitizing or validating the configuration["PASSWORD"] argument within the connect/remote upload/remote download function in the main.py file. As a temporary workaround, restrict access to the Configuration File Handler component.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10767

Affected Products

Cosmodiumcs Onlyrat