CVE-2025-69771

An arbitrary file upload vulnerability in the subtitle loading function of asbplayer v1.13.0 allows attackers to execute arbitrary code via uploading a crafted subtitle file.
References
Link Resource
http://chrome.com Not Applicable
http://killergerbah.com Broken Link
https://reve-offensive.tistory.com/35 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:killergerbah:asbplayer:*:*:*:*:*:chrome:*:*

History

02 Mar 2026, 19:37

Type Values Removed Values Added
References () http://chrome.com - () http://chrome.com - Not Applicable
References () http://killergerbah.com - () http://killergerbah.com - Broken Link
References () https://reve-offensive.tistory.com/35 - () https://reve-offensive.tistory.com/35 - Third Party Advisory
First Time Killergerbah asbplayer
Killergerbah
CPE cpe:2.3:a:killergerbah:asbplayer:*:*:*:*:*:chrome:*:*

26 Feb 2026, 20:31

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.6

25 Feb 2026, 16:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 16:23

Updated : 2026-03-02 19:37


NVD link : CVE-2025-69771

Mitre link : CVE-2025-69771

CVE.ORG link : CVE-2025-69771


JSON object : View

Products Affected

killergerbah

  • asbplayer
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type