CVE-2025-5129 is a critical uncontrolled search path vulnerability affecting Sangfor 零信任访问控制系统 aTrust version 2.3.10.60, specifically within the MSASN1.dll library. This vulnerability requires local access and user interaction for exploitation, with a high attack complexity, making it difficult to exploit. Despite public disclosure of the exploit, there is no evidence of active exploitation, nor are there any known Metasploit, Nuclei, or ExploitDB modules available. Community discussion and media coverage are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.10.60CPE matchmatch criteria | cpe:2.3:a:sangfor:atrust:2.3.10.60:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.