BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.
History

Thu, 09 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Oct 2025 16:15:00 +0000


Thu, 09 Oct 2025 16:00:00 +0000

Type Values Removed Values Added
Description BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.
Title Improper Archive Extraction in unarchive Enables RCE
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: BLSOPS

Published:

Updated: 2025-10-09T17:38:35.196Z

Reserved: 2025-09-11T16:19:05.900Z

Link: CVE-2025-10284

cve-icon Vulnrichment

Updated: 2025-10-09T17:38:32.052Z

cve-icon NVD

Status : Received

Published: 2025-10-09T16:15:44.077

Modified: 2025-10-09T16:15:44.077

Link: CVE-2025-10284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.