CVE-2025-48501 CRITICAL

CVE-2025-48501

Vendor Nimesa
Product Nimesa Backup and Recovery
Weakness CWE-78
Published July 7, 2025
Last update July 7, 2025

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.

Key dates

02Disclosure timeline

July 7, 2025 CVE published
July 7, 2025 Record updated