CVE-2025-6267
Last modified
CVE-2025-6267 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated as critical. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. It has been rated as critical. This issue affects some unknown processing of the file /adpweb/a/base/barcodeDetail/. The manipulation of the argument barcodeNo/barcode/itemNo leads to sql injection. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zhilink | Adp Application Developer Platform | 1.0.0 |
References
- https://vuldb.com/?ctiid.313271Permissions Required, VDB Entry
- https://vuldb.com/?id.313271Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.586697Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6267?
How severe is CVE-2025-6267?
How do I fix CVE-2025-6267?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62664Improper Neutralization of Input During Web Page Generation …6.9
- CVE-2025-62665Improper Neutralization of Input During Web Page Generation …6.9
- CVE-2025-62666Allocation of Resources Without Limits or Throttling vulnera…6.9
- CVE-2025-62667Improper Neutralization of Input During Web Page Generation …6.9
- CVE-2025-62668Incorrect Default Permissions vulnerability in The Wikimedia…6.9
- CVE-2025-62669Exposure of Sensitive Information to an Unauthorized Actor v…6.9
- CVE-2025-62670Improper Neutralization of Input During Web Page Generation …6.9
- CVE-2025-62671Improper Neutralization of Input During Web Page Generation …6.9
- CVE-2025-62672rplay through 3.3.2 allows attackers to cause a denial of se…5.3
- CVE-2025-62673Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0…8
- CVE-2025-62674The affected product allows unauthenticated access to Real T…7
- CVE-2025-62675An Improper Neutralization of CRLF Sequences in HTTP Headers…4.3
Are you affected by CVE-2025-6267?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
