CVE-2025-10353 is a critical remote code execution (RCE) vulnerability affecting the "melis-cms-slider" module within Melis Technology's Melis Platform. It allows an unauthenticated attacker to upload malicious files via a POST request to a specific endpoint, leading to arbitrary code execution. With a CVSS score of 9.3 (Critical) and a FAUCET Risk Score of 97/100, this vulnerability presents a significant risk due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, Nuclei templates for exploitation are publicly available, and it has garnered substantial community discussion, indicating active interest in its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Melis Technology | Melis Platform | >= 0, < 5.3.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.