CVE-2025-4125: ISPSoft File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Apr 30, 2025
·Updated
Delta Electronics ISPSoft version 3.20 is vulnerable to an Out-Of-Bounds Write vulnerability that could allow an attacker to execute arbitrary code when parsing ISP file.
Affected Software
2 affected components
Delta Electronics ISPSoft
Deltaww Ispsoft<3.21
Remediation
Information
Download and update to: v3.21 or later
Event History
Apr 30, 2025
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-4125?
CVE-2025-4125 has been assigned a high severity rating due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2025-4125?
To fix CVE-2025-4125, update Delta Electronics ISPSoft to the latest version where the vulnerability has been patched.
3
What are the potential impacts of CVE-2025-4125?
The potential impacts of CVE-2025-4125 include unauthorized access and control over the affected system through arbitrary code execution.
4
Which versions of ISPSoft are affected by CVE-2025-4125?
CVE-2025-4125 specifically affects Delta Electronics ISPSoft version 3.20.
5
What type of vulnerability is CVE-2025-4125?
CVE-2025-4125 is classified as an Out-Of-Bounds Write vulnerability.