Remote Code Execution Vulnerability in SS1 by Dos Co.
CVE-2025-53970
9.3CRITICAL
What is CVE-2025-53970?
A vulnerability exists in SS1 versions 16.0.0.10 and earlier that allows remote unauthenticated attackers to upload arbitrary files. This exploit can lead to execution of operating system commands with elevated SYSTEM privileges, posing significant security risks to affected systems.
Affected Version(s)
SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) (Affected under Windows environment only)
SS1 Cloud Ver.2.1.3 and earlier (Affected under Windows environment only)
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved