CVE-2025-36846 Details
Description
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec() function of PHP. NOTE: this can be chained with CVE-2025-36845.
A command injection vulnerability has been identified in Eveo URVE Web Manager version 27.02.2025. The issue arises from an endpoint exposed to unauthenticated users, which allows for operating system command injection via the shell_exec() function in PHP. This vulnerability can be exploited by sending crafted requests that include malicious commands, potentially leading to unauthorized execution of commands on the server.
Users are advised to update to the latest version of URVE Web Manager and block all endpoints under /_internal/ from external requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://smartoffice.expert/en/ | [email protected] | Product |
| https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-034.txt | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| eveo urve web manager | 27.02.2025 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 12, 2025 | Initial Analysis | [email protected] |
| Jul 21, 2025 | CVE Modified | CISA-ADP |
| Jul 21, 2025 | New CVE Received | [email protected] |