CVE-2025-8610 is a critical remote code execution vulnerability affecting AOMEI Cyber Backup, specifically within its StorageNode service on TCP port 9075. This flaw allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges due to a missing authentication mechanism. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk, requiring no user interaction or prior authentication for exploitation. While there is no known active exploitation or public exploit code available, the vulnerability has garnered community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.7.0CPE matchmatch criteria | cpe:2.3:a:aomei:cyber_backup:3.7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.