CVE-2025-29902 is a critical remote code execution (RCE) vulnerability (CWE-94) affecting the Telex Remote Dispatch Console Server v1.0.0, allowing unauthenticated attackers to execute arbitrary code on the server. With a CVSS score of 10.0 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation. Organizations using the affected product should restrict access and monitor closely as no patch is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Telex | Remote Dispatch Console Server | >= 1.0.0, < 1.3.0CNA affected | |
| RTS | VLink Virtual Matrix Software | >= 6.0.0, < 6.6.0, 5CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remote Code Execution in Telex RDC Server and RTS VLink Virtual Matrix
Jun 10, 2025Remote Code Execution in Telex RDC Server and RTS VLink Virtual Matrix
Jun 10, 2025Remote Code Execution in Telex RDC Server and RTS VLink Virtual Matrix
Jun 10, 2025Remote Code Execution in Telex RDC Server and RTS VLink Virtual Matrix
Jun 10, 2025Remote Code Execution in Telex RDC Server and RTS VLink Virtual Matrix
Jun 10, 2025Remote Code Execution in Telex RDC Server and RTS VLink Virtual Matrix
Jun 10, 2025