PT-2025-39393 · Unknown · Geyang Ml-Logger
0X1F
·
Published
2025-09-25
·
Updated
2025-09-25
·
CVE-2025-10950
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
geyang ml-logger (affected versions not specified)
Description
A flaw exists in geyang ml-logger. The
log handler function within the ml logger/server.py file, specifically in the Ping Handler component, is susceptible to deserialization due to manipulation of the data argument. This issue can be triggered remotely. The exploit has been publicly disclosed. As this product uses a rolling release model, specific version details for affected or updated releases are unavailable.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Geyang Ml-Logger