CVE-2025-3600General(progress / telerik_ui_for_asp.net_ajax)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-470

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • telerik_ui_for_asp.net_ajax

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-04); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
telerik_ui_for_asp.net_ajax

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-04: 1Mentions · 2026-02-19: 1Technical Details · 2026-02-04: 1Technical Details · 2026-02-19: 102-0402-19
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-041
General1
2026-02-191
Disclosure1
Full discourse2 posts
  • reverseame@reverseame
    General

    More Than DoS (Progress Telerik UI for http://ASP.NET AJAX Unsafe Reflection CVE-2025-3600) #CVE20253600 #TelerikUI #UnsafeReflection #RCE #ASPNetSecurity https://labs.watchtowr.com/more-than-dos-progress-telerik-ui-for-asp-net-ajax-unsafe-reflection-cve-2025-3600/

    Post summary

    The tweet references CVE-2025-3600, highlighting unsafe reflection that could lead to RCE, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    030921.1K
    21.6K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 (LangChain #Redis Checkpointer), Query Injection, #CVE-2025-3600 (Critical) https://dailycve.com/langchain-redis-checkpointer-query-injection-cve-2025-3600-critical/

    Post summary

    CVE‑2025‑3600 is a newly disclosed critical query injection flaw in LangChain Redis Checkpointer; the post does not provide PoC or exploitation details.

    0000037
    162 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprogresstelerik_ui_for_asp.net_ajax---

Explore more