CVE-2025-53508
Last modified
CVE-2025-53508 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed and sensitive information may be obtained. EPSS estimates a 1.29% chance of exploitation in the next 30 days.
Description
Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed and sensitive information may be obtained. As for the details of affected product names and versions, refer to the information under [Product Status].
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-53508?
How severe is CVE-2025-53508?
How do I fix CVE-2025-53508?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-53502Improper Input Validation vulnerability in Wikimedia Foundat…6.5
- CVE-2025-53503Trend Micro Cleaner One Pro is vulnerable to a Privilege Esc…7.8
- CVE-2025-53504Group-Office versions prior to 6.8.119 and prior to 25.0.20 …5.4
- CVE-2025-53505Group-Office versions prior to 6.8.119 and prior to 25.0.20 …5.3
- CVE-2025-53506Uncontrolled Resource Consumption vulnerability in Apache To…7.5
- CVE-2025-53507Multiple products provided by iND Co.,Ltd contain an insecur…7.1
- CVE-2025-53509A vulnerability exists in Advantech iView that allows for ar…7.1
- CVE-2025-5351A flaw was found in the key export functionality of libssh. …6.5
- CVE-2025-53510A memory corruption vulnerability exists in the PSD Image De…8.8
- CVE-2025-53511A heap-based buffer overflow vulnerability exists in the MFE…9.8
- CVE-2025-53512The /log endpoint on a Juju controller lacked sufficient aut…6.5
- CVE-2025-53513The /charms endpoint on a Juju controller lacked sufficient …6.5
Are you affected by CVE-2025-53508?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
