CVE-2025-36846 | Eveo URVE Web Manager 27.02.2025 Endpoint /_internal/pc/vpro.php shell_exec os command injection
A vulnerability was found in Eveo URVE Web Manager 27.02.2025. It has been declared as critical. Affected by this vulnerability is the function shell_exec of the file /_internal/pc/vpro.php of the component Endpoint. The manipulation leads to os command injection.
This vulnerability is known as CVE-2025-36846. The attack needs to be initiated within the local network. There is no exploit available.