CVE-2025-48501
CVE-2025-48501
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.3EPSS 1.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
07 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Nimesa · Nimesa Backup and Recovery