CVE-2025-3413 Details
Description
A vulnerability has been found in opplus springboot-admin up to a2d5310f44fd46780a8686456cf2f9001ab8f024 and classified as critical. Affected by this vulnerability is the function code of the file SysGeneratorController.java. The manipulation of the argument Tables leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
A critical deserialization vulnerability has been identified in Opplus Spring Boot Admin versions prior to commit a2d5310f44fd46780a8686456cf2f9001ab8f024. The issue arises in the SysGeneratorController.java file, where improper handling of the Tables argument allows for remote deserialization attacks. This vulnerability has been publicly disclosed and could be exploited in the wild.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mapl3miss/Vul/blob/main/Vul.md | CISA-ADP | Broken Link |
| https://github.com/mapl3miss/Vul/blob/main/Vul.md | [email protected] | Broken Link |
| https://vuldb.com/?ctiid.303691 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.303691 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.545374 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opplus springboot-admin | <= 2017-12-26 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | Initial Analysis | [email protected] |
| Apr 8, 2025 | CVE Modified | CISA-ADP |
| Apr 8, 2025 | New CVE Received | [email protected] |