CVE-2025-30057: Cgm Clininet
Critical severity, CVSS 9.4. EPSS: 0.7% chance of exploitation in the next 30 days.
In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.
Affected products
- Cgm Cgm Clininet: before 2024.MS4 (fixed in 2024.MS4)
Published 2025-08-27. Last modified 2026-06-17.