OS Command Injection Vulnerability in vsDesk Software by vsDesk
CVE-2025-14601

8.6HIGH

Key Information:

Vendor

Vsdesk

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2025-14601?

An OS command injection flaw in vsDesk allows authenticated users with administrative access to execute arbitrary commands on the operating system. Due to inadequate input filtering, attackers can exploit this vulnerability to compromise server operations, extract sensitive information, or gain complete control over the web server. It is essential for users to apply the latest patch available from the vendor to mitigate these risks.

Affected Version(s)

vsDesk 11.06.02

vsDesk 14.0101

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)
.