CVE-2025-7916: CWE-502 Deserialization of Untrusted Data in Simopro Technology WinMatrix3
WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents.
CVE-2025-7916: CWE-502 Deserialization of Untrusted Data in Simopro Technology WinMatrix3
Description
WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized contents.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- twcert
- Date Reserved
- 2025-07-21T01:58:23.151Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 687ddb26a83201eaac09b82f
Added to database: 7/21/2025, 6:16:06 AM
Last updated: 7/21/2025, 6:16:06 AM
Views: 1
Related Threats
CVE-2025-7918: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Simopro Technology WinMatrix3 Web package
CriticalCVE-2025-7917: CWE-434 Unrestricted Upload of File with Dangerous Type in Simopro Technology WinMatrix3 Web package
HighCVE-2025-7915: SQL Injection in Chanjet CRM
MediumCVE-2025-7914: Buffer Overflow in Tenda AC6
HighCVE-2025-7913: Buffer Overflow in TOTOLINK T6
HighActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.