SQL Injection Vulnerability in CentrosNet by DIAL
CVE-2025-10870
9.3CRITICAL
What is CVE-2025-10870?
A SQL injection vulnerability exists in DIAL's CentrosNet v2.64, where attackers can manipulate input through the 'ultralogin' parameter in '/centrosnet/ultralogin.php'. This enables unauthorized users to retrieve, create, update, or delete database records by sending crafted POST and GET requests, raising significant security concerns for users of the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CentrosNet prior to 2.65
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Arnau Yepes
