CVE-2025-2566

Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated attacker can make specially crafted requests to execute arbitrary code on the server.
CVSS

No CVSS.

Configurations

No configuration.

History

26 Jun 2025, 18:58

Type Values Removed Values Added
Summary
  • (es) Kaleris NAVIS N4 ULC (Cliente Ultraligero) contiene una vulnerabilidad de deserialización de Java insegura. Un atacante no autenticado puede realizar solicitudes especialmente manipuladas para ejecutar código arbitrario en el servidor.

24 Jun 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-24 19:15

Updated : 2025-06-26 18:58


NVD link : CVE-2025-2566

Mitre link : CVE-2025-2566

CVE.ORG link : CVE-2025-2566


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data