CVE-2025-3621CRITICAL 9.6EPSS p52.2%
CVE-2025-3621CVE-2025-3621
Description
Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on host systems.
* vulnerabilities:
*
Improper Neutralization of Special Elements used in a Command ('Command Injection')
* Use of Hard-coded Credentials
* Improper Authentication
* Binding to an Unrestricted IP Address
The vulnerability has been rated as critical.This issue affects ActADUR: from v2.0.1.9 before v2.0.2.0., hence updating to version v2.0.2.0. or above is required.
Scoring
| CVSS 3.1 | 9.6 (CRITICAL) |
| Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
| EPSS | 0.81% probability of exploitation · percentile 52.2% · 2026-06-18T12:00:27Z |
| Published | 2025-07-15 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 4
References
4
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Binding to an Unrestricted IP Addresscwe-1327 | 0% | live |
| Weakness | Improper Authenticationcwe-287 | 0% | live |
| Weakness | Improper Neutralization of Special Elements used in a Command ('Command Injection')cwe-77 | 0% | live |
| Weakness | Use of Hard-coded Credentialscwe-798 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.