AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-32868

HIGH · CVSS 8.8 EPSS 0.41%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-04-16 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable. It involves a SQL injection risk.

CVE
CVE-2025-32868
Severity
HIGH
CVSS
8.8
EPSS
0.41%

Original NVD Description

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ExportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

Related CVEs

Other vulnerabilities affecting the same vendor(s)