CVE-2025-4272 Mechrevo Control Console GCUService csCAPI.dll uncontrolled search path

Vulnerability Details

Basic Information

Title CVE-2025-4272 Mechrevo Control Console GCUService csCAPI.dll uncontrolled search path
Type vulnrichment
Published 2025-05-05T11:00:07
Last Seen 2025-05-05T13:32:34
CVSS Score 7.0 (HIGH)

CVSS v3 Details

Attack Vector LOCAL
Attack Complexity HIGH
Privileges Required LOW
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

CVE Information

CVE IDs CVE-2025-4272
CWE CWE-427, CWE-426
Bulletin Family cve

Description

A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is some unknown functionality in the library C:\Program Files\OEM\MECHREVO Control Center\UniwillService\MyControlCenter\csCAPI.dll of the component GCUService. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

Impact Assessment

Base Score 7.0
Severity HIGH

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.