CVE-2025-4905 is a critical deserialization vulnerability (CWE-502) affecting iop-apl-uw basestation3 up to version 3.0.4, specifically within the load_qc_pickl function of the basestation3/QC.py file. This flaw allows for arbitrary code execution due to improper input validation (CWE-20) when manipulating the qc_file argument. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk, as it can be exploited remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While the issue is publicly disclosed and the maintainer has marked it as closed, there are no available patches or new releases, and no active exploitation or exploit intelligence (Metasploit, Nuclei, ExploitDB) has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, <= 3.0.4CPE matchmatch criteria | cpe:2.3:a:washington:basestation:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.