Vulnerability in UPS Management Software by OMRON SOCIAL SOLUTIONS
CVE-2025-9818

6.7MEDIUM

What is CVE-2025-9818?

A vulnerability has been found in the UPS management application by OMRON SOCIAL SOLUTIONS Co., Ltd., stemming from improperly defined executable file paths in its Windows services. The lack of quotation marks around these paths creates a security loophole when the installation folder contains spaces, potentially permitting unauthorized files to execute with the privileges of the service. This flaw highlights the critical need for secure coding practices to prevent exploitation.

Affected Version(s)

PowerAct Pro <Master Agent> Windows 0 <= 5.17

PowerAct Pro <Slave Agent> Windows 0 <= 5.20

PowerAttendant Basic Edition Windows 0 <= 1.1.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9818 : Vulnerability in UPS Management Software by OMRON SOCIAL SOLUTIONS