2025年6月13日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • Freefloat Ftp Server:公開エクスプロイトまたは PoC が関連付けられました (Buffer Overflow)
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

悪用活動を確認

CVE-2025-49113 RoundCube Webmail Deserialization of Untrusted Data

  • 公開エクスプロイトまたは PoC あり
  • 悪用活動が関連付け
  • リモートコード実行の露出リスク

Roundcube Webmail RCE に公開エクスプロイトまたは PoC が関連 — 日和見的スキャンと続く標的型活動を想定してください。

悪用活動を確認

CVE-2025-5548 A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0.

  • 公開エクスプロイトまたは PoC あり
  • 悪用活動が関連付け

Freefloat Ftp Server Buffer Overflow に公開エクスプロイトまたは PoC が関連 — 日和見的スキャンと続く標的型活動を想定してください。

重大な露出リスク

CVE-2025-28386 Openc3 Cosmos RCE

  • CVSS 9.8
  • リモートコード実行の露出リスク

新たな重大 Openc3 Cosmos RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

CVE-2025-5548 悪用

A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0.

RoundCube Webmail Deserialization of Untrusted Data

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing o...

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2025-28384 CVSS 9.1

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

CVE-2025-28386 CVSS 9.8

A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitr...

CVE-2025-28388 CVSS 9.8

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

CVE-2025-28389 CVSS 9.8

Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.

CVE-2025-45987 CVSS 9.8

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC...

CVE-2025-45988 CVSS 9.8

Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC...

CVE-2025-46060 CVSS 9.8

Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_...

CVE-2025-49596 CVSS 9.4

The MCP inspector is a developer tool for testing and debugging MCP servers.

CVE-2025-6029 CVSS 9.4

Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-branded Aftermarket...

CVE-2025-6030 CVSS 9.4

Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyclone Matrix TRF S...

Critical 公開を見る

cvelogic Threat Intelligence