CVE-2025-48501
Last modified
CVE-2025-48501 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-48501?
How severe is CVE-2025-48501?
How do I fix CVE-2025-48501?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-48496Emerson ValveLink products use a fixed or controlled search…5.9
- CVE-2025-48497Cross-site request forgery vulnerability exists in iroha Boa…5.1
- CVE-2025-48498A null pointer dereference vulnerability exists in the Distr…7.5
- CVE-2025-48499Out-of-bounds write vulnerability exists in FUJIFILM Busines…6.9
- CVE-2025-4850A vulnerability classified as critical has been found in TOT…6.3
- CVE-2025-48500A missing file integrity check vulnerability exists on MacOS…7.3
- CVE-2025-48502Improper input validation within AMD uprof can allow a local…5.5
- CVE-2025-48503A DLL hijacking vulnerability in the AMD Software Installer …7.8
- CVE-2025-48505Weak permissions in the Vitis™ Unified installation path on …1
- CVE-2025-48506Uncontrolled search paths in Vitis™ Unified installation pat…4.6
- CVE-2025-48507The security state of the calling processor into Trusted Fir…8.6
- CVE-2025-48508Improper Hardware reset flow logic in the GPU GFX Hardware I…6
Are you affected by CVE-2025-48501?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
