CVE-2025-57644
Last modified
CVE-2025-57644 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request forgery (SSRF), enabling interaction with internal or external systems. Successful exploitation can lead to full server compromise, unauthorized access to sensitive data, and further network exploitation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Accela | Automation Platform | 22.2.3.0.230103 |
References
- https://medium.com/@anvarkh/cve-2025-57644-remote-code-execution-ssrf-in-accela-eedc6bc4adfbMitigation, Third Party Advisory
- https://www.accela.comProduct
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-57644?
How severe is CVE-2025-57644?
How do I fix CVE-2025-57644?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-57636OS Command injection vulnerability in D-Link C1 2020-02-21. …6.5
- CVE-2025-57637Buffer overflow vulnerability in D-Link DI-7100G 2020-02-21 …7.5
- CVE-2025-57638Buffer overflow vulnerability in Tenda AC9 1.0 via the user …7.5
- CVE-2025-57639OS Command injection vulnerability in Tenda AC9 1.0 was disc…6.5
- CVE-2025-5764A vulnerability was found in code-projects Laundry System 1.…5.4
- CVE-2025-57642A Shell Upload vulnerability in Tourism Management System 2.…7.2
- CVE-2025-5765A vulnerability was found in code-projects Laundry System 1.…5.4
- CVE-2025-5766A vulnerability was found in code-projects Laundry System 1.…4.3
- CVE-2025-57665Element Plus Link component (el-link) through 2.10.6 impleme…6.4
- CVE-2025-5767The Crowdfunding for WooCommerce plugin for WordPress is vul…6.4
- CVE-2025-57681The WorklogPRO - Timesheets for Jira plugin in Jira Data Cen…5.4
- CVE-2025-57682Directory Traversal vulnerability in Papermark 0.20.0 and pr…6.5
Are you affected by CVE-2025-57644?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
