PT-2026-3061 · Noaa Pmel · Live Access Server

Published

2026-01-15

·

Updated

2026-01-15

·

CVE-2025-62193

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NOAA PMEL Live Access Server (LAS) (affected versions not specified)
Description Sites running NOAA PMEL Live Access Server (LAS) are susceptible to remote code execution through specially crafted requests containing PyFerret expressions. An unauthenticated, remote attacker can leverage a SPAWN command to execute arbitrary operating system commands. The issue involves a component named gov.noaa.pmel.tmap.las.filter.RequestInputFilter.java, which was updated on 2025-09-24.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-62193

Affected Products

Live Access Server