Search

Find a vulnerability

Search criteria

    4 vulnerabilities by Raisecom

    CVE-2026-19764 (GCVE-0-2026-19764)

    Vulnerability from nvd โ€“ Published: 2026-08-14 00:45 โ€“ Updated: 2026-08-14 14:55
    VLAI
    Title
    Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection
    Summary
    A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-08-14 14:54 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/389667 vdb-entrytechnical-description
    https://vuldb.com/vuln/389667/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-19764 third-party-advisory
    https://vuldb.com/submit/868986 third-party-advisory
    https://my.feishu.cn/docx/S80ddLulfolH8WxDbUJcdrGโ€ฆ exploit
    Impacted products
    Vendor Product Version
    Raisecom Communication Command and Dispatch Management Platform Affected: 7.6.0
    Affected: 7.6.1
    Affected: 7.6.2
    Affected: 7.6.3
    Affected: 7.6.4
    Affected: 7.6.5
        cpe:2.3:a:raisecom:communication_command_and_dispatch_management_platform:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-19764",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-14T14:54:54.986258Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-14T14:55:36.100Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:raisecom:communication_command_and_dispatch_management_platform:*:*:*:*:*:*:*:*"
              ],
              "product": "Communication Command and Dispatch Management Platform",
              "vendor": "Raisecom",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.0"
                },
                {
                  "status": "affected",
                  "version": "7.6.1"
                },
                {
                  "status": "affected",
                  "version": "7.6.2"
                },
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "affected",
                  "version": "7.6.4"
                },
                {
                  "status": "affected",
                  "version": "7.6.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "0menc (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-14T00:45:50.967Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-389667 | Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/389667"
            },
            {
              "name": "VDB-389667 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/389667/cti"
            },
            {
              "name": "CVE-2026-19764 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-19764"
            },
            {
              "name": "Submit #868986 | Raisecom Technology Co., Ltd. Raisecom Communication Command and Dispatch Management Platform 7.6.5 SQL Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/868986"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://my.feishu.cn/docx/S80ddLulfolH8WxDbUJcdrGAnbg?from=from_copylink"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-08-13T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-08-13T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-08-13T18:52:05.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection",
          "x_generator": [
            "VulDB PVTS v202608"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-19764",
        "datePublished": "2026-08-14T00:45:50.967Z",
        "dateReserved": "2026-08-13T16:47:00.376Z",
        "dateUpdated": "2026-08-14T14:55:36.100Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1536 (GCVE-0-2025-1536)

    Vulnerability from nvd โ€“ Published: 2025-02-21 14:31 โ€“ Updated: 2025-02-21 16:46
    VLAI
    Title
    Raisecom Multi-Service Intelligent Gateway Request Parameter vpn_template_style.php os command injection
    Summary
    A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the file /vpn/vpn_template_style.php of the component Request Parameter Handler. The manipulation of the argument stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2025-02-21 16:42 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.296476 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.296476 signaturepermissions-required
    https://vuldb.com/?submit.497021 third-party-advisory
    https://github.com/koishi0x01/CVE/blob/main/CVE_1.md exploit
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1536",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-21T16:42:14.976352Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-21T16:46:38.199Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Request Parameter Handler"
              ],
              "product": "Multi-Service Intelligent Gateway",
              "vendor": "Raisecom",
              "versions": [
                {
                  "status": "affected",
                  "version": "20250208"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "KOISH1 (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the file /vpn/vpn_template_style.php of the component Request Parameter Handler. The manipulation of the argument stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
            },
            {
              "lang": "de",
              "value": "In Raisecom Multi-Service Intelligent Gateway bis 20250208 wurde eine Schwachstelle ausgemacht. Sie wurde als kritisch eingestuft. Das betrifft eine unbekannte Funktionalit\u00e4t der Datei /vpn/vpn_template_style.php der Komponente Request Parameter Handler. Durch Manipulation des Arguments stylenum mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-21T14:31:04.960Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-296476 | Raisecom Multi-Service Intelligent Gateway Request Parameter vpn_template_style.php os command injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.296476"
            },
            {
              "name": "VDB-296476 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.296476"
            },
            {
              "name": "Submit #497021 | Raisecom Technology Co., Ltd. Raisecom Multi-Service Intelligent Gateway vpn_template_style.php Command Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.497021"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/koishi0x01/CVE/blob/main/CVE_1.md"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-02-21T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-02-21T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-02-21T08:05:16.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Raisecom Multi-Service Intelligent Gateway Request Parameter vpn_template_style.php os command injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-1536",
        "datePublished": "2025-02-21T14:31:04.960Z",
        "dateReserved": "2025-02-21T07:00:12.316Z",
        "dateUpdated": "2025-02-21T16:46:38.199Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-19764 (GCVE-0-2026-19764)

    Vulnerability from cvelistv5 โ€“ Published: 2026-08-14 00:45 โ€“ Updated: 2026-08-14 14:55
    VLAI
    Title
    Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection
    Summary
    A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-08-14 14:54 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/389667 vdb-entrytechnical-description
    https://vuldb.com/vuln/389667/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-19764 third-party-advisory
    https://vuldb.com/submit/868986 third-party-advisory
    https://my.feishu.cn/docx/S80ddLulfolH8WxDbUJcdrGโ€ฆ exploit
    Impacted products
    Vendor Product Version
    Raisecom Communication Command and Dispatch Management Platform Affected: 7.6.0
    Affected: 7.6.1
    Affected: 7.6.2
    Affected: 7.6.3
    Affected: 7.6.4
    Affected: 7.6.5
        cpe:2.3:a:raisecom:communication_command_and_dispatch_management_platform:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-19764",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-14T14:54:54.986258Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-14T14:55:36.100Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:raisecom:communication_command_and_dispatch_management_platform:*:*:*:*:*:*:*:*"
              ],
              "product": "Communication Command and Dispatch Management Platform",
              "vendor": "Raisecom",
              "versions": [
                {
                  "status": "affected",
                  "version": "7.6.0"
                },
                {
                  "status": "affected",
                  "version": "7.6.1"
                },
                {
                  "status": "affected",
                  "version": "7.6.2"
                },
                {
                  "status": "affected",
                  "version": "7.6.3"
                },
                {
                  "status": "affected",
                  "version": "7.6.4"
                },
                {
                  "status": "affected",
                  "version": "7.6.5"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "0menc (VulDB User)"
            },
            {
              "lang": "en",
              "type": "coordinator",
              "value": "VulDB CNA Team"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "SQL Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-74",
                  "description": "Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-14T00:45:50.967Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-389667 | Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/389667"
            },
            {
              "name": "VDB-389667 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/389667/cti"
            },
            {
              "name": "CVE-2026-19764 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-19764"
            },
            {
              "name": "Submit #868986 | Raisecom Technology Co., Ltd. Raisecom Communication Command and Dispatch Management Platform 7.6.5 SQL Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/868986"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://my.feishu.cn/docx/S80ddLulfolH8WxDbUJcdrGAnbg?from=from_copylink"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-08-13T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-08-13T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-08-13T18:52:05.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Raisecom Communication Command and Dispatch Management Platform getpwd.php sql injection",
          "x_generator": [
            "VulDB PVTS v202608"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-19764",
        "datePublished": "2026-08-14T00:45:50.967Z",
        "dateReserved": "2026-08-13T16:47:00.376Z",
        "dateUpdated": "2026-08-14T14:55:36.100Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-1536 (GCVE-0-2025-1536)

    Vulnerability from cvelistv5 โ€“ Published: 2025-02-21 14:31 โ€“ Updated: 2025-02-21 16:46
    VLAI
    Title
    Raisecom Multi-Service Intelligent Gateway Request Parameter vpn_template_style.php os command injection
    Summary
    A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the file /vpn/vpn_template_style.php of the component Request Parameter Handler. The manipulation of the argument stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2025-02-21 16:42 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/?id.296476 vdb-entrytechnical-description
    https://vuldb.com/?ctiid.296476 signaturepermissions-required
    https://vuldb.com/?submit.497021 third-party-advisory
    https://github.com/koishi0x01/CVE/blob/main/CVE_1.md exploit
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-1536",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-21T16:42:14.976352Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-21T16:46:38.199Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Request Parameter Handler"
              ],
              "product": "Multi-Service Intelligent Gateway",
              "vendor": "Raisecom",
              "versions": [
                {
                  "status": "affected",
                  "version": "20250208"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "KOISH1 (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Raisecom Multi-Service Intelligent Gateway up to 20250208. It has been declared as critical. This vulnerability affects unknown code of the file /vpn/vpn_template_style.php of the component Request Parameter Handler. The manipulation of the argument stylenum leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
            },
            {
              "lang": "de",
              "value": "In Raisecom Multi-Service Intelligent Gateway bis 20250208 wurde eine Schwachstelle ausgemacht. Sie wurde als kritisch eingestuft. Das betrifft eine unbekannte Funktionalit\u00e4t der Datei /vpn/vpn_template_style.php der Komponente Request Parameter Handler. Durch Manipulation des Arguments stylenum mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Der Angriff kann \u00fcber das Netzwerk angegangen werden. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 6.9,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 7.5,
                "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "OS Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "Command Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-21T14:31:04.960Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-296476 | Raisecom Multi-Service Intelligent Gateway Request Parameter vpn_template_style.php os command injection",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/?id.296476"
            },
            {
              "name": "VDB-296476 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.296476"
            },
            {
              "name": "Submit #497021 | Raisecom Technology Co., Ltd. Raisecom Multi-Service Intelligent Gateway vpn_template_style.php Command Injection",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/?submit.497021"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/koishi0x01/CVE/blob/main/CVE_1.md"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2025-02-21T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2025-02-21T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2025-02-21T08:05:16.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Raisecom Multi-Service Intelligent Gateway Request Parameter vpn_template_style.php os command injection"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2025-1536",
        "datePublished": "2025-02-21T14:31:04.960Z",
        "dateReserved": "2025-02-21T07:00:12.316Z",
        "dateUpdated": "2025-02-21T16:46:38.199Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }