go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

NetVision Information airPASS - SQL injection

TVN ID TVN-202501001
CVE ID CVE-2025-0455
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products airPASS v2.9.0.x, v3.0.0.x
Description The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution For v2.9.0.x, please update to version 2.9.0.241231 or later.
For v3.0.0.x, please update to version 3.0.0.241231 or later.
Credit Security member
Public Date 2025-01-15
Top