Remote Code Execution Vulnerability in PointCloudLibrary by OpenNURBS
CVE-2025-52937

2LOW

Key Information:

Status
Vendor
CVE Published:
23 June 2025

What is CVE-2025-52937?

A vulnerability has been identified in the PointCloudLibrary related to the OpenNURBS modules, specifically within the crc32.C program files. Users who are utilizing versions prior to 1.14.0 or have opted not to employ the system zlib by setting WITH_SYSTEM_ZLIB to FALSE may find their systems at risk. This flaw can potentially allow for remote code execution, posing significant threats to the integrity and security of affected applications. It is crucial for users to upgrade to the latest version of PointCloudLibrary to mitigate this risk.

Affected Version(s)

pcl 0 < 1.14.0

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TITAN Team ([email protected])
.
CVE-2025-52937 : Remote Code Execution Vulnerability in PointCloudLibrary by OpenNURBS