CVE-2025-10350: Cgm Netraad

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0.

Affected products

  • Cgm Cgm Netraad: before 7.9.0 (fixed in 7.9.0)

Published 2026-03-02. Last modified 2026-06-17.