PT-2025-3891 · Netvision Information · Airpass

Published

2025-01-16

·

Updated

2025-01-16

·

CVE-2025-0455

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions airPASS versions (affected versions not specified)
Description The airPASS from NetVision Information has a SQL Injection issue, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. This enables attackers to manipulate database content remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-0455

Affected Products

Airpass