CVE-2025-7145

Published Jul 7, 2025

Last updated 10 days ago

Overview

Description
ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermediate privileges to inject arbitrary OS commands and execute them on the server, thereby gaining administrative access to the remote host.
Source
twcert@cert.org.tw
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.6
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
7.2
Impact score
5.9
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

twcert@cert.org.tw
CWE-78

Social media

Hype score
Not currently trending
  1. CVE-2025-7145 (CVSS:8.6, HIGH) is Awaiting Analysis. ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers wit..https://t.co/npw4J1M6TT #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    11 Jul 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-7145 | TeamT5 ThreatSonar Anti-Ransomware up to 3.8.3 os command injection (EUVD-2025-20167) https://t.co/nuA0enTBBi A vulnerability was found in TeamT5 ThreatSonar Anti-Ransomware up to 3.8.3. It has been declared as critical. Affected by this vulnerability is an unkn

    @f1tym1

    7 Jul 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-7145 | TeamT5 ThreatSonar Anti-Ransomware up to 3.8.3 os command injection https://t.co/nuA0enTBBi A vulnerability was found in TeamT5 ThreatSonar Anti-Ransomware up to 3.8.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality.

    @f1tym1

    7 Jul 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-7145 OS Command Injection in ThreatSonar Anti-Ransomware Enables Remote Administrative Access https://t.co/pPXj0XJ3B8

    @VulmonFeeds

    7 Jul 2025

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-7145: HIGH] Beware! ThreatSonar Anti-Ransomware by TeamT5 has an OS Command Injection vulnerability, enabling attackers to execute arbitrary OS commands remotely and gain admin access.#cve,CVE-2025-7145,#cybersecurity https://t.co/fWMdAOlNN4 https://t.co/OffZtpnswz

    @CveFindCom

    7 Jul 2025

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes