CVE-2025-28386: Code Injection
Published Jun 13, 2025
·Updated
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.
Affected Software
3 affected components
OpenC3 COSMOS
OpenC3 COSMOS=6.0.0
OpenC3 COSMOS=6.0.0
Event History
Jun 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-28386?
CVE-2025-28386 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-28386?
To mitigate CVE-2025-28386, update OpenC3 COSMOS to the latest patched version that addresses this vulnerability.
3
What type of attack does CVE-2025-28386 allow?
CVE-2025-28386 allows attackers to execute arbitrary code on the affected system through a crafted .txt file upload.
4
Which component of OpenC3 COSMOS is affected by CVE-2025-28386?
The vulnerability is found in the Plugin Management component of OpenC3 COSMOS.
5
Is CVE-2025-28386 exploitable remotely?
Yes, CVE-2025-28386 can be exploited remotely, allowing attackers to execute code from outside the system.