PT-2025-41301 · Unknown · Curo Uc300

Restdone

·

Published

2025-10-08

·

Updated

2025-10-11

·

CVE-2025-57457

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Curo UC300 version 5.42.1.7.1.63R1
Description A flaw exists within the Admin panel that permits local attackers to inject arbitrary OS Commands. The injection occurs through the IP Addr parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-57457

Affected Products

Curo Uc300