CVE-2025-1546 Details
Description
A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A critical OS command injection vulnerability has been identified in the BDCOM Behavior Management and Auditing System, affecting versions prior to 20250210. The issue arises in the 'log_operate_clear' function within the '/webui/modules/log/operate.mds' file. The vulnerability allows remote attackers to execute arbitrary system commands by manipulating the 'start_code' parameter, exploiting inadequate input validation. This exploitation can lead to unauthorized access and control over the server, with potential impacts on core business data and operations.
BDCOM has been contacted about this vulnerability but has not responded. Users are advised to monitor for any official patches or updates from the vendor.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 21, 2025CISA-ADP
Assessed Feb 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/koishi0x01/CVE/blob/main/CVE_2.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/?ctiid.296491 | [email protected] | Content WallTechnical Description |
| https://vuldb.com/?id.296491 | [email protected] | Content WallTechnical Description |
| https://vuldb.com/?submit.497558 | [email protected] | Content WallTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Shanghai Baud DATA Communicatior Internet Behavior Management and Auditing System | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 13, 2025 | CVE Modified | CISA-ADP |
| Aug 26, 2025 | CVE Modified | CISA-ADP |
| Feb 21, 2025 | CVE Modified | CISA-ADP |
| Feb 21, 2025 | New CVE Received | [email protected] |
Volerion