CVE-2025-2147
Last modified
CVE-2025-2147 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Beijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints are affected. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Caishixiong | Modern Farm Digital Integrated Management System | 1.0 |
References
- https://vuldb.com/?ctiid.299058Permissions Required
- https://vuldb.com/?id.299058Permissions Required
- https://vuldb.com/?submit.506593Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-2147?
How severe is CVE-2025-2147?
How do I fix CVE-2025-2147?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21464Information disclosure while reading data from an image usin…6.5
- CVE-2025-21465Information disclosure while processing the hash segment in …6.5
- CVE-2025-21466Memory corruption while processing a private escape command …7.8
- CVE-2025-21467Memory corruption while reading the FW response from the sha…7.8
- CVE-2025-21468Memory corruption while reading response from FW, when buffe…7.8
- CVE-2025-21469Memory corruption while processing image encoding, when inpu…7.8
- CVE-2025-21470Memory corruption while processing image encoding, when conf…7.8
- CVE-2025-21472Information disclosure while capturing logs as eSE debug mes…5.5
- CVE-2025-21473Memory corruption when using Virtual cdm (Camera Data Mover)…7
- CVE-2025-21474Memory corruption while processing commands from A2dp sink c…7.8
- CVE-2025-21475Memory corruption while processing escape code, when Display…7.8
- CVE-2025-21476Memory corruption when passing parameters to the Trusted Vir…7.8
Are you affected by CVE-2025-2147?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
