Remote Code Execution Vulnerability in SS1 by Dos Co.
CVE-2025-53970

9.3CRITICAL

Key Information:

Vendor
CVE Published:
28 August 2025

What is CVE-2025-53970?

A vulnerability exists in SS1 versions 16.0.0.10 and earlier that allows remote unauthenticated attackers to upload arbitrary files. This exploit can lead to execution of operating system commands with elevated SYSTEM privileges, posing significant security risks to affected systems.

Affected Version(s)

SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under Windows environment only)

SS1 Cloud Ver.2.1.3 and earlier (Affected under Windows environment only)

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53970 : Remote Code Execution Vulnerability in SS1 by Dos Co.