CVE-2025-8769 describes a critical remote code execution vulnerability in the Telenium Online Web Application. This flaw stems from improper input validation in a Perl script responsible for loading the login page, allowing attackers to inject arbitrary Perl code via crafted HTTP requests. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| MegaSys Computer Technologies | Telenium Online Web Application | >= 0, <= 8.3CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.