PT-2025-39393 · Unknown · Geyang Ml-Logger

0X1F

·

Published

2025-09-25

·

Updated

2025-09-25

·

CVE-2025-10950

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions geyang ml-logger (affected versions not specified)
Description A flaw exists in geyang ml-logger. The log handler function within the ml logger/server.py file, specifically in the Ping Handler component, is susceptible to deserialization due to manipulation of the data argument. This issue can be triggered remotely. The exploit has been publicly disclosed. As this product uses a rolling release model, specific version details for affected or updated releases are unavailable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-10950
GHSA-57HM-8RJV-498W

Affected Products

Geyang Ml-Logger