A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.
References
| Link | Resource |
|---|---|
| https://b1tsec.gitbook.io/offensive-repo/cve-repository/cve-2025-66715 | Third Party Advisory |
| https://www.axtion.nl/odis/ | Product |
Configurations
History
22 Jan 2026, 21:44
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:axtion:odis:*:*:*:*:*:*:*:* | |
| First Time |
Axtion
Axtion odis |
|
| References | () https://b1tsec.gitbook.io/offensive-repo/cve-repository/cve-2025-66715 - Third Party Advisory | |
| References | () https://www.axtion.nl/odis/ - Product |
09 Jan 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-77 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
09 Jan 2026, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-09 20:15
Updated : 2026-01-22 21:44
NVD link : CVE-2025-66715
Mitre link : CVE-2025-66715
CVE.ORG link : CVE-2025-66715
JSON object : View
Products Affected
axtion
- odis
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
