CVE-2025-57457
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS Commands via the "IP Addr" parameter.
Published 2025-10-08. Last modified 2026-07-05.