CVE-2025-50515: Command Injection
Published Aug 14, 2025
·Updated
An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the config file was loaded.
Affected Software
1 affected component
Phome Empirebak
Event History
Aug 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-50515?
The severity of CVE-2025-50515 is considered high due to the potential for arbitrary code execution.
2
How do I fix CVE-2025-50515?
To fix CVE-2025-50515, you should update to the latest version of Phome Empirebak or apply any available security patches.
3
What systems are affected by CVE-2025-50515?
CVE-2025-50515 affects Phome Empirebak 2010 specifically in its ebak2008/upload/class/config.php component.
4
What type of vulnerability is CVE-2025-50515?
CVE-2025-50515 is a vulnerability that allows attackers to execute arbitrary code.
5
Who is the vendor for CVE-2025-50515?
The vendor for CVE-2025-50515 is Phome, which develops the Empirebak software.