CRITICAL🇵🇱 Wersja polska

CVE-2025-40671

CVSS 9.3v4.0pub. 2025-05-26upd. 2026-04-15

SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘fk_remoto_central’ parameter on the ‘/webservices/articles.php’ endpoint.

🤖 AI Analysis
How it works

The vulnerability occurs in the 'fk_remoto_central' parameter handled by the '/webservices/articles.php' endpoint. The application does not filter or parameterize user-supplied input data, allowing an attacker to inject malicious SQL queries directly into the database engine. The attack requires no authentication or user interaction, and can be carried out remotely over the network.

Impact

An attacker can read, create, modify, and delete any data stored in the application's database. In practice, this means the possibility of stealing sensitive information, data manipulation, or complete destruction of database contents.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Additional temporary measures may include restricting network access to the '/webservices/articles.php' endpoint exclusively to trusted IP addresses and implementing Web Application Firewall (WAF) rules blocking typical SQL injection patterns.

Who is affected

AES Multimedia Gestnet version 1.07

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References