Remote Code Execution Vulnerability in roncoo-pay by Roncoo
CVE-2025-10287
What is CVE-2025-10287?
A security vulnerability has been identified in the roncoo-pay system, implicating the /auth/orderQuery function. This vulnerability allows an attacker to manipulate the 'orderNo' argument, potentially leading to unauthorized remote requests. The attack complexity is deemed high, making it challenging to exploit. As the product utilizes a rolling release system, details regarding specific versions affected or remediated are not provided. Despite early disclosure of the issue to the vendor, there has been no response from them regarding this security flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
roncoo-pay 9428382af21cd5568319eae7429b7e1d0332ff40
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
