Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2025-69600

AI Predicted 7.8 Difficulty: Moderate EPSS 0.11% · P28

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
n/an/an/aaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-69600

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Command injection in Raynet rvia 12.6.4392.49-amd64.deb allows adversaries to execute commands via getconfig, and upload through the URL argument, and oracle through the -o flag The Supplier's perspective is that this is caused by Argument Injection in the find command query in rvia 12.6.4392.49. This in an arbitrary code execution flaw caused by an incorrectly constructed find command. The application actively searches for a Java executable by using search criteria that is not properly terminated or sanitized. By constructing a crafted directory path that satisfies the malformed search criteria, an attacker can trick the application into executing arbitrary Java code. This differs from standard PATH manipulation because it stems from the application's internal search logic. Specifically, a local attacker can create a crafted directory structure and path that satisfies an improperly terminated find query used by the application to locate a Java runtime.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2025-69600

#POC DescriptionSource LinkShenlong Link
1Nonehttps://github.com/Wise-Security/CVE-2025-69600POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-69600

登录查看更多情报信息。

Other References for CVE-2025-69600 (1)

Same Patch Batch · n/a · 2026-05-27 · 28 CVEs total

CVE-2026-360448.8 HIGH@pensar/apex<=0.0.58 OS命令注入
CVE-2026-43905.4 MEDIUMTeamSpeak 3 Server Connection State Management process_resend_queue use after free
CVE-2026-43915.3 MEDIUMTeamSpeak 3 Server ECC Key heap-based overflow
CVE-2026-43925.3 MEDIUMTeamSpeak 3 Server clientek Handshake assertion
CVE-2026-33552Mender Enterprise Server <4.1.1 访问控制错误漏洞
CVE-2026-49009Mender Server路径遍历漏洞
CVE-2025-67903Mender Client 5<5.0.4 存在密码学签名验证绕过漏洞
CVE-2026-38808uzy-ssm-mall v1.1.0 SQL注入漏洞
CVE-2026-38807kvf-admin v1.0.0 不安全权限提升漏洞
CVE-2025-70116GPAC MP4Box NULL指针解引用导致崩溃
CVE-2025-68712AppLock 7.9.40绕过认证漏洞
CVE-2026-38930OpenRapid RapidCMS v1.3.1 认证绕过漏洞
CVE-2026-38931SimplePHP存储型XSS漏洞
CVE-2026-38945Raynet rvia 12.6.4392.49 命令注入漏洞
CVE-2025-70103libjxl 0.12.0 PBM解析堆溢出漏洞
CVE-2026-30498AdminPanel 4.0 CSRF漏洞
CVE-2026-31266Craft CMS<5.9.5 迁移接口权限缺失漏洞
CVE-2026-37711Dolibarr远程代码执行漏洞
CVE-2026-37712Dolibarr ERP/CRM远程代码执行漏洞
CVE-2026-37713Dolibarr ERP/CRM 22.x-24.0-alpha 远程代码执行漏洞

Showing top 20 of 28 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-69600

No comments yet


Leave a comment