CVE-2025-63617: Kutangguo Ktg-Mes

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.

Affected products

  • Kutangguo Ktg-Mes: before 2025-10-08 (fixed in 2025-10-08)

Published 2025-11-10. Last modified 2026-06-17.