File Access Vulnerability in SS1 by DOS Osaka
CVE-2025-52460

6.9MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2025

What is CVE-2025-52460?

A vulnerability exists in SS1 versions 16.0.0.10 and earlier, as well as Media version 16.0.0a and earlier, that allows unauthenticated remote attackers to access sensitive files and configuration data. This flaw can lead to unauthorized information disclosure, exposing critical configuration files and uploaded documents to external entities.

Affected Version(s)

SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under Windows environment only)

SS1 Cloud Ver.2.1.3 and earlier (Affected under Windows environment only)

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52460 : File Access Vulnerability in SS1 by DOS Osaka