CVE-2025-9060 – MSoft MFlash Remote Code Execution Vulnerability

The following table lists the changes that have been made to the
CVE-2025-9060 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 15, 2025

    Action Type Old Value New Value
    Added Description A vulnerability has been found in the  MSoft MFlash

    application that allows
    execution of arbitrary code on the server. The issue occurs in the
    integration configuration functionality that is only available to
    MFlash

    administrators. The vulnerability is related to insufficient validation
    of parameters when setting up security components.

    This issue affects MFlash v. 8.0 and possibly others. To mitigate apply 8.2-653 hotfix 11.06.2025 and above.

    Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
    Added CWE CWE-20
    Added Reference https://github.com/klsecservices/Advisories/blob/master/K-MSoft-2025-002.md
Share the Post:

Related Posts