CVE-2019-3025 is a critical vulnerability affecting Oracle Hospitality RES 3700 version 5.7, allowing an unauthenticated attacker to achieve full system takeover. Despite being difficult to exploit via network access (HTTP), successful attacks can significantly impact additional products beyond RES 3700, leading to complete compromise of confidentiality, integrity, and availability. With a CVSS v3.0 base score of 9.0 (CRITICAL) and a FAUCET Risk Score of 97/100, this vulnerability poses a severe threat. While not listed in CISA's KEV catalog or showing active exploitation, a public exploit (EDB-48477) for Remote Code Execution exists, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.7CPE matchmatch criteria | cpe:2.3:a:oracle:hospitality_res_3700:5.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.