PT-2025-48977 · Hcltech · Hcltech Gragon

Published

2025-12-03

·

Updated

2025-12-03

·

CVE-2025-63402

CVSS v3.1

5.5

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions HCLTech GRAGON versions prior to 7.6.0
Description A flaw exists in HCLTech GRAGON that could allow a remote attacker to execute arbitrary code. This occurs because the APIs do not enforce limits on the number or size of requests.
Recommendations Update to version 7.6.0 or later.

Fix

RCE

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-63402

Affected Products

Hcltech Gragon