Home

Description

An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter.

PUBLISHED Reserved 2025-08-17 | Published 2025-10-08 | Updated 2025-10-08 | Assigner mitre

References

curo.com

github.com/restdone/CVE-2025-57457/tree/main

cve.org (CVE-2025-57457)

nvd.nist.gov (CVE-2025-57457)

Download JSON