cvedb.io
CVE-2025-57794
CRITICAL · CVSS 9.1
EPSS exploitation probability: 0%
Published 2026-01-28T18:16:49.707 · Last modified 2026-06-17T09:43:26.810

Summary

Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This condition enables remote code execution under default configurations.

Affected products

explorance — blue

Does this affect you?

Add your gear to cvedb and we'll alert you only when explorance ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.