CVE-2025-9818: Vulnerability caused by unquoted file paths of Windows services registered by the Uninterruptible Power Supply (UPS) management application
A vulnerability (CWE-428) has been identified in the Uninterruptible Power Supply (UPS) management application provided by OMRON SOCIAL SOLUTIONS Co., Ltd., where the executable file paths of Windows services are not enclosed in quotation marks. If the installation folder path of this product contains spaces, there is a possibility that unauthorized files may be executed under the service privileges by using paths containing spaces.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9818?
CVE-2025-9818 has a moderate severity rating due to the potential risk of unauthorized execution of arbitrary commands.
How do I fix CVE-2025-9818?
To fix CVE-2025-9818, ensure that all executable file paths for the Windows services are enclosed in quotation marks.
What impact does CVE-2025-9818 have on the OMRON UPS Management Application?
CVE-2025-9818 can lead to command injection vulnerabilities, allowing attackers to execute unauthorized commands.
Which versions of OMRON UPS Management Application are affected by CVE-2025-9818?
All versions of OMRON UPS Management Application that do not properly handle executable file paths are affected by CVE-2025-9818.
Is there a known exploit for CVE-2025-9818?
As of now, there is no publicly known exploit specifically targeting CVE-2025-9818, but the vulnerability poses a significant risk.