CVE-2025-55270 is a critical improper input validation vulnerability (CWE-20) affecting HCL Aftermarket DPC (hcltech aftermarket_cloud) that allows attackers to inject executable code. Rated 9.8 Critical on CVSS, this flaw is network-exploitable with low complexity and no privileges or user interaction required, enabling severe impacts such as XSS, SQL Injection, and Command Injection, leading to high confidentiality, integrity, and availability compromise. There is currently no evidence of active exploitation, nor are public exploit codes available in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:hcltech:aftermarket_cloud:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.