PT-2025-4141 · Myscada · Myscada Mypro

Mehmet Ince

·

Published

2024-09-13

·

Updated

2025-03-25

·

CVE-2025-20061

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions mySCADA myPRO (affected versions not specified)
Description The issue concerns the inadequate neutralization of POST requests sent to a specific port with email information. This could be exploited by an attacker to execute arbitrary commands on the affected system. There is evidence of active exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02942
CVE-2025-20061
ZDI-25-088

Affected Products

Myscada Mypro