CVE-2025-34039: Yonyou NC BeanShell Command Injection
A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to execute arbitrary Java code via the bsh.script parameter. This can be exploited to run system commands and ultimately gain full control over the target server. The issue is rooted in a third-party JAR component bundled with the application, and the servlet is accessible without authentication on vulnerable installations. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34039?
CVE-2025-34039 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2025-34039?
To fix CVE-2025-34039, users should upgrade Yonyou UFIDA NC to version 6.6 or later.
What impact does CVE-2025-34039 have on my system?
CVE-2025-34039 allows unauthenticated attackers to execute arbitrary Java code on affected systems.
Which versions of Yonyou UFIDA NC are affected by CVE-2025-34039?
Yonyou UFIDA NC versions 6.5 and earlier are affected by CVE-2025-34039.
Is authentication required to exploit CVE-2025-34039?
No, CVE-2025-34039 can be exploited by unauthenticated remote attackers.