ZDI-25-894: Digilent WaveForms DWF3WORK File Parsing Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Digilent WaveForms. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-10203.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-894?
The ZDI-25-894 vulnerability has been assigned a significant CVSS rating, indicating a high severity risk.
How do I fix ZDI-25-894?
To mitigate ZDI-25-894, users should update Digilent WaveForms to the latest version that addresses this vulnerability.
What type of attack does ZDI-25-894 enable?
ZDI-25-894 allows remote attackers to execute arbitrary code on affected installations of Digilent WaveForms.
Is user interaction required for exploiting ZDI-25-894?
Yes, user interaction is required, as the victim must visit a malicious page or open a malicious file.
Which software is affected by ZDI-25-894?
The vulnerability ZDI-25-894 affects installations of Digilent WaveForms.