CVE-2025-14601
CVE-2025-14601 is a high-severity vulnerability with a CVSS 4.0 base score of 8.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-676.
Key facts
- Severity: High (CVSS 4.0 base score 8.6)
- EPSS exploit prediction: 1% (54th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-676
- Published:
- Last modified:
Description
An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Frequently asked questions
- What is CVE-2025-14601?
- An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
- How severe is CVE-2025-14601?
- CVE-2025-14601 has a CVSS 4.0 base score of 8.6, rated high severity.
- Is CVE-2025-14601 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (54th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2025-14601?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2025-14601 published?
- CVE-2025-14601 was published on 2026-08-20.
References
Other CWE-676 vulnerabilities
- CVE-2021-27474 — Critical (CVSS 10.0): Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS…
- CVE-2022-39063 — High (CVSS 7.5): When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for building the PFCP Session…
- CVE-2025-65117 — High (CVSS 7.4): The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed…
- CVE-2024-38434 — Medium (CVSS 6.5): Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass
- CVE-2024-50307 — Medium (CVSS 5.5): Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2.…
- CVE-2025-67604 — Medium (CVSS 5.3): A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer…