CVE-2025-14601Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. An attacker can exploit this flaw to disrupt web server operations, expose sensitive data, or potentially achieve full server compromise. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-676

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-20: 2Technical Details · 2026-08-20: 208-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-14601 An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to … https://www.cve.org/CVERecord?id=CVE-2025-14601 ----- Traducción: CVE-2025-14601 Una… https://infoflow.cloud`

    Post summary

    The post announces CVE‑2025‑14601, detailing an OS command injection flaw in vsDesk that permits authenticated administrators to run arbitrary OS commands. No exploit code, patch notice, or evidence of active exploitation is provided.

    0000019
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-14601 An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to … https://www.cve.org/CVERecord?id=CVE-2025-14601

    Post summary

    The post announces CVE-2025-14601, an OS command injection flaw in vsDesk that permits administrators to run arbitrary system commands, with no further details on PoC, exploitation, or mitigation.

    00000611
    58.0K followersView on X

Explore more