Remote Code Comparison Vulnerability in HuangDou UTCMS 9 Login Component
CVE-2025-9401
Key Information:
Badges
What is CVE-2025-9401?
A vulnerability exists within the login component of HuangDou UTCMS 9, specifically in the app/modules/ut-frame/admin/login.php file. The vulnerability allows for incorrect comparison due to manipulation of the argument code, which can be exploited remotely. While the complexity of the attack is considered high, the exploit has been disclosed publicly, raising concerns about potential attacks. Although the vendor was notified about the issue, there has been no response, making this a critical area of concern for users of the affected product.
Affected Version(s)
UTCMS 9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved