CVE-2025-3753
Last modified
CVE-2025-3753 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function to process unsanitized, user-supplied input in the 'rosbag filter' command. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function to process unsanitized, user-supplied input in the 'rosbag filter' command. This flaw enables attackers to craft and execute arbitrary Python code.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openrobotics | Robot Operating System | indigo_igloo |
| Openrobotics | Robot Operating System | kinetic_kame |
| Openrobotics | Robot Operating System | melodic_morenia |
| Openrobotics | Robot Operating System | noetic_ninjemys |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3753?
How severe is CVE-2025-3753?
How do I fix CVE-2025-3753?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-3747Rejected reason: This CVE ID was duplicated of CVE-2025-3280…
- CVE-2025-3748The Taxonomy Chain Menu plugin for WordPress is vulnerable t…5.4
- CVE-2025-3749The Breeze Display plugin for WordPress is vulnerable to Sto…6.4
- CVE-2025-3750The Network Posts Extended plugin for WordPress is vulnerabl…6.4
- CVE-2025-3751The component listed above contains a vulnerability that can…7
- CVE-2025-3752The Able Player, accessible HTML5 media player plugin for Wo…6.4
- CVE-2025-3755Improper Validation of Specified Index, Position, or Offset …9.1
- CVE-2025-3756A vulnerability exists in the command handling of the IEC 61…7.1
- CVE-2025-3757Versions of OpenPubkey library prior to 0.10.0 contained a …9.8
- CVE-2025-3758WF2220 exposes endpoint /cgi-bin-igd/netcore_get.cgi that re…8.7
- CVE-2025-3759Endpoint /cgi-bin-igd/netcore_set.cgi which is used for chan…8.7
- CVE-2025-3760A stored cross-site scripting (XSS) vulnerability exists wit…5.4
Are you affected by CVE-2025-3753?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
