CVE-2025-51746: Critical severity jishenghua JSH_ERP vulnerability
Published Nov 25, 2025
·Updated
An issue was discovered in jishenghua JSHERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.
Affected Software
2 affected components
jishenghua JSH_ERP
jishenghua jshERP<=2.3.1
Event History
Nov 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51746?
CVE-2025-51746 has been classified with a high severity due to its potential for exploitation via deserialization attacks.
2
How do I fix CVE-2025-51746?
To fix CVE-2025-51746, it is recommended to update to the latest version of Jishenghua JSH_ERP that addresses this vulnerability.
3
What systems are affected by CVE-2025-51746?
CVE-2025-51746 affects Jishenghua JSH_ERP version 2.3.1.
4
What kind of attack is associated with CVE-2025-51746?
CVE-2025-51746 is associated with fastjson deserialization attacks which can allow unauthorized actions or data manipulation.
5
How can I determine if my system is vulnerable to CVE-2025-51746?
You can determine if your system is vulnerable to CVE-2025-51746 by checking if you are running Jishenghua JSH_ERP version 2.3.1 or lower.