6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If exploited, uploaded files and SS1 configuration files may be accessed by a remote unauthenticated attacker.
Basic Information
ID
CVE-2025-52460
Source
jpcert
Published
Aug 28, 2025 at 08:27
Affected Product
Vendor
DOS Co., Ltd.
Product
SS1
Version
Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under Windows environment only)
Affected Versions
DOS Co., Ltd. SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under Windows environment only)
DOS Co., Ltd. SS1 Cloud Ver.2.1.3 and earlier (Affected under Windows environment only)
DOS Co., Ltd. SS1 Cloud Ver.2.1.3 and earlier (Affected under Windows environment only)