CVE-2025-48501: Nimesa Backup And Recovery
Critical severity, CVSS 9.3. EPSS: 1.3% chance of exploitation in the next 30 days.
An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an arbitrary OS commands may be executed on the server where the product is running.
Affected products
- Nimesa Nimesa Backup And Recovery: version v2.3 only; version v2.4 only
Published 2025-07-07. Last modified 2026-06-17.