CVE-2025-63402: Medium severity HCL Technologies HCLTech GRAGON vulnerability
Published Dec 3, 2025
·Updated
An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code via APIs do not enforcing limits on the number or size of requests
Affected Software
2 affected components
HCL Technologies HCLTech GRAGON<7.6.0
hcltech DRAGON<7.6.0
Event History
Dec 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63402?
CVE-2025-63402 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-63402?
To fix CVE-2025-63402, upgrade HCLTech GRAGON to version 7.6.0 or later.
3
What type of attack does CVE-2025-63402 facilitate?
CVE-2025-63402 allows remote attackers to execute arbitrary code by exploiting unregulated API request limits.
4
Which versions of HCLTech GRAGON are impacted by CVE-2025-63402?
Versions of HCLTech GRAGON before v.7.6.0 are affected by CVE-2025-63402.
5
Is there a workaround for CVE-2025-63402 until a patch is available?
Currently, there is no documented workaround for CVE-2025-63402, and upgrading to the latest version is recommended.