CVE-2025-10326
MiczFlor RPi-Jukebox-RFID single.php os command injection
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.3EPSS 7.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
12 set 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single.php. Performing manipulation of the argument playlist results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
MiczFlor · RPi-Jukebox-RFIDQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →