CVE-2025-9000

A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component reg File Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gX Broken Link
https://vuldb.com/?ctiid.320029 Permissions Required VDB Entry
https://vuldb.com/?id.320029 Third Party Advisory VDB Entry
https://vuldb.com/?submit.624903 Third Party Advisory VDB Entry
https://vuldb.com/?submit.624903 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:mechrevo:control_center_gx_v2:5.56.51.48:*:*:*:*:*:*:*

History

11 Sep 2025, 18:14

Type Values Removed Values Added
References () https://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gX - () https://drive.proton.me/urls/7QYSEW6734#H3N4fQ3mw6gX - Broken Link
References () https://vuldb.com/?ctiid.320029 - () https://vuldb.com/?ctiid.320029 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.320029 - () https://vuldb.com/?id.320029 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.624903 - () https://vuldb.com/?submit.624903 - Third Party Advisory, VDB Entry
Summary
  • (es) Se encontró una vulnerabilidad en Mechrevo Control Center GX V2 5.56.51.48. Esta vulnerabilidad afecta a una funcionalidad desconocida del componente "reg File Handler". Esta manipulación genera una ruta de búsqueda incontrolada. Es posible lanzar el ataque al host local. Es un ataque de complejidad bastante alta. Parece difícil de explotar. Se ha hecho público el exploit y puede que sea utilizado.
First Time Mechrevo
Mechrevo control Center Gx V2
CPE cpe:2.3:a:mechrevo:control_center_gx_v2:5.56.51.48:*:*:*:*:*:*:*

15 Aug 2025, 13:15

Type Values Removed Values Added
References () https://vuldb.com/?submit.624903 - () https://vuldb.com/?submit.624903 -

15 Aug 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-15 02:15

Updated : 2025-09-11 18:14


NVD link : CVE-2025-9000

Mitre link : CVE-2025-9000

CVE.ORG link : CVE-2025-9000


JSON object : View

Products Affected

mechrevo

  • control_center_gx_v2
CWE
CWE-426

Untrusted Search Path

CWE-427

Uncontrolled Search Path Element