VDB

CVE-2025-32866

CVE-2025-32866 PUBLISHED CVSS 8.800000190734863 HIGH

A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetLogs' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the application's database and execute code with "NT AUTHORITY\NetworkService" permissions. A successful attack requires the attacker to be able to access port 8000 on a system where a vulnerable version of the affected application is executed on.

EPSS 0.05% · 17.4th percentile

Risk Scores

CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.05%
17.4th percentile

Affected Products

VendorProductVersions
SiemensTeleControl Server Basic0
siemenstelecontrol_server_basic0

Timeline

  • Apr 16, 2025 CVE Published
  • Apr 16, 2025 PoC Published
  • Apr 16, 2025 PoC Published
  • Apr 16, 2025 PoC Published
  • Apr 17, 2025 EPSS Score
  • Apr 22, 2025 PoC Published
  • Apr 29, 2025 EPSS Score
  • May 3, 2025 Coalition ESS Score
  • May 12, 2025 EPSS Score
  • May 24, 2025 EPSS Score
  • Jun 5, 2025 EPSS Score
  • Jun 18, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›