OS Command Injection Vulnerability in vsDesk Software by vsDesk
CVE-2025-14601
8.6HIGH
What is CVE-2025-14601?
An OS command injection flaw in vsDesk allows authenticated users with administrative access to execute arbitrary commands on the operating system. Due to inadequate input filtering, attackers can exploit this vulnerability to compromise server operations, extract sensitive information, or gain complete control over the web server. It is essential for users to apply the latest patch available from the vendor to mitigate these risks.
Affected Version(s)
vsDesk 11.06.02
vsDesk 14.0101
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)
