CVE-2025-3002 Details
Description
A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
A critical OS command injection vulnerability has been identified in the Digital China DCME-520 gateway, affecting versions through 20250320. The issue arises from an unknown processing flaw in the file '/usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php', where the 'type_name' argument can be manipulated to inject and execute arbitrary commands on the operating system. This vulnerability can be exploited remotely, and while the primary injection point has been disclosed, other parameters may also be susceptible.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 31, 2025CISA-ADP
Assessed Mar 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Fizz-L/CVE1/blob/main/DCME-520%20Remote%20command%20execution.md | CISA-ADP | ExploitTechnical Description |
| https://github.com/Fizz-L/CVE1/blob/main/DCME-520%20Remote%20command%20execution.md | [email protected] | ExploitTechnical Description |
| https://vuldb.com/?ctiid.302051 | [email protected] | Content Wall |
| https://vuldb.com/?id.302051 | [email protected] | Content Wall |
| https://vuldb.com/?submit.524225 | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Digital China DCME-520 | <= 20250320 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2025 | CVE Modified | CISA-ADP |
| Mar 31, 2025 | New CVE Received | [email protected] |
Volerion