PT-2025-45415 · Dial · Centrosnet

·

CVE-2025-10870

·

Published

2025-11-07

·

Updated

2025-11-07

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions DIAL CentrosNet versions prior to 2.65
Description A SQL injection issue exists in DIAL's CentrosNet. An attacker can retrieve, create, update, and delete databases by sending POST and GET requests. The vulnerability is present in the /centrosnet/ultralogin.php file, specifically through the ultralogin parameter. This allows for unauthenticated database control.
Recommendations Update DIAL CentrosNet to version 2.65 or later. As a temporary workaround, restrict access to the /centrosnet/ultralogin.php file. Avoid using the ultralogin parameter in POST and GET requests until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10870

Affected Products

Centrosnet