PT-2026-7604 · Zilab · Zilab Remote Console Server

Cakes

·

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2019-25309

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zilab Remote Console Server version 3.2.9
Description The software contains an unquoted service path that could allow local attackers to execute arbitrary code with elevated system privileges. Exploitation involves leveraging the unquoted binary path within the service configuration to inject malicious executables, which are then executed with LocalSystem permissions.
Recommendations Ensure the service path is enclosed in quotes to prevent the execution of unauthorized code.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-25309

Affected Products

Zilab Remote Console Server