9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.
Basic Information
ID
CVE-2025-53970
Source
jpcert
Published
Aug 28, 2025 at 08:28
Affected Product
Vendor
DOS Co., Ltd.
Product
SS1
Version
Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under Windows environment only)
Affected Versions
DOS Co., Ltd. SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under Windows environment only)
DOS Co., Ltd. SS1 Cloud Ver.2.1.3 and earlier (Affected under Windows environment only)
DOS Co., Ltd. SS1 Cloud Ver.2.1.3 and earlier (Affected under Windows environment only)