PT-2025-47112 · Thinplus · Thinplus

Published

2025-11-17

·

Updated

2025-11-22

·

CVE-2025-13284

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThinPLUS (affected versions not specified)
Description ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability. This allows unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. The vulnerability offers trivial remote code execution with zero barriers to entry.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-13284

Affected Products

Thinplus