CVE-2025-10326
MiczFlor RPi-Jukebox-RFID single.php os command injection
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 7.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
12 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single.php. Performing manipulation of the argument playlist results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
MiczFlor · RPi-Jukebox-RFID¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →