PT-2025-48158 · Opencode Systems · Opencode Systems Ussd Gateway

Published

2025-11-26

·

Updated

2025-12-02

·

CVE-2025-65236

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenCode Systems USSD Gateway version 5
Description The OpenCode Systems USSD Gateway contains a SQL injection flaw. This issue is located in the /occontrolpanel/index.php API endpoint through the Session ID parameter. Successful exploitation could allow an attacker to manipulate database queries.
Recommendations Apply any available updates to address the SQL injection flaw in the /occontrolpanel/index.php endpoint. As a temporary workaround, restrict access to the /occontrolpanel/index.php endpoint. Sanitize the Session ID parameter to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-65236

Affected Products

Opencode Systems Ussd Gateway