CVE 9.4 CRITICAL

Calling system commands via RunCommand_CVE-2025-30056

9.4 / 10
CRITICAL
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on the system.

Basic Information

ID CVE-2025-30056
Source CERT-PL
Published Aug 27, 2025 at 10:23

Affected Product

Vendor CGM
Product CGM CLININET
Affected Versions CGM CGM CLININET 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.