CVE-2025-63617

ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kutangguo:ktg-mes:*:*:*:*:*:*:*:*

History

05 Feb 2026, 15:10

Type Values Removed Values Added
References () https://gist.github.com/ChangeYourWay/8651679a2155269bccf520fcb34fc661 - () https://gist.github.com/ChangeYourWay/8651679a2155269bccf520fcb34fc661 - Third Party Advisory
References () https://github.com/ChangeYourWay/post/blob/main/ktg-mes.md - () https://github.com/ChangeYourWay/post/blob/main/ktg-mes.md - Exploit, Third Party Advisory
Summary
  • (es) ktg-mes anterior al commit a484f96 (2025-07-03) tiene una vulnerabilidad de deserialización de fastjson. Esto se debe a que utiliza una versión vulnerable de fastjson y deserializa datos de entrada inseguros.
First Time Kutangguo ktg-mes
Kutangguo
CPE cpe:2.3:a:kutangguo:ktg-mes:*:*:*:*:*:*:*:*

12 Nov 2025, 21:15

Type Values Removed Values Added
CWE CWE-502
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

10 Nov 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-10 21:15

Updated : 2026-02-05 15:10


NVD link : CVE-2025-63617

Mitre link : CVE-2025-63617

CVE.ORG link : CVE-2025-63617


JSON object : View

Products Affected

kutangguo

  • ktg-mes
CWE
CWE-502

Deserialization of Untrusted Data