CVE-2025-0364 is a critical unauthenticated remote code execution vulnerability affecting BigAntSoft BigAnt Server up to and including version 5.6.06. An attacker can register an administrative account via a default exposed SaaS mechanism, then upload and execute arbitrary PHP code through the "Cloud Storage Addin." This flaw carries a CVSS score of 9.8 (Critical), indicating a network-based attack with low complexity and complete compromise of confidentiality, integrity, and availability. While there is no known public exploit code or KEV listing, the vulnerability has garnered community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.6.06CPE matchmatch criteria | cpe:2.3:a:bigantsoft:bigant_server:*:*:*:*:*:*:*:* | ||
>= 0, <= 5.6.06CPE match | cpe:2.3:a:bigantsoft:bigant_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.