CVE-2025-10767 - CosmodiumCS OnlyRAT Os Command Injection Vulnerability

CVE ID : CVE-2025-10767
Published : Sept. 22, 2025, 1:08 a.m. | 54 minutes ago
Description : A vulnerability was detected in CosmodiumCS OnlyRAT up to 3.2. The affected element is the function connect/remote_upload/remote_download of the file main.py of the component Configuration File Handler. The manipulation of the argument configuration["PASSWORD"] results in os command injection. The attack requires a local approach. Attacks of this nature are highly complex. The exploitability is described as difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/qXU02Od
via IFTTT

Post a Comment

Please Select Embedded Mode To Show The Comment System.*

Previous Post Next Post