Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

11 Billion Transactions and 26% Exclusion: The Infrastructure Hole the CBN Desires to Shut

March 13, 2026

Microsoft newest within the Large Tech race for AI well being instruments

March 13, 2026

Commodities Report: Gold pauses above USD 5000 as vitality shock clouds the worldwide outlook – Insights from Saxo Financial institution

March 13, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • 11 Billion Transactions and 26% Exclusion: The Infrastructure Hole the CBN Desires to Shut
  • Microsoft newest within the Large Tech race for AI well being instruments
  • Commodities Report: Gold pauses above USD 5000 as vitality shock clouds the worldwide outlook – Insights from Saxo Financial institution
  • Google Fixes Two Chrome Zero-Days Exploited within the Wild Affecting Skia and V8
  • Hisense TVs Now Show Adverts When You Change Inputs, Boot Up
  • China’s Sensible Driving Corps Launches a Head-On Problem
  • Your BVN telephone quantity can now solely be modified as soon as
  • How you can Resolve the “Couldn’t learn reactor desk model” Error for SOLIDWORKS PDM
Friday, March 13
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - Pre-Auth Exploit Chains Present in Commvault May Allow Distant Code Execution Assaults
Cybersecurity & Digital Rights

Pre-Auth Exploit Chains Present in Commvault May Allow Distant Code Execution Assaults

NextTechBy NextTechAugust 22, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Pre-Auth Exploit Chains Present in Commvault May Allow Distant Code Execution Assaults
Share
Facebook Twitter LinkedIn Pinterest Email


Aug 21, 2025Ravie LakshmananVulnerability / Software program Safety

Commvault has launched updates to handle 4 safety gaps that might be exploited to realize distant code execution on vulnerable cases.

The record of vulnerabilities, recognized in Commvault variations earlier than 11.36.60, is as follows –

  • CVE-2025-57788 (CVSS rating: 6.9) – A vulnerability in a identified login mechanism permits unauthenticated attackers to execute API calls with out requiring person credentials
  • CVE-2025-57789 (CVSS rating: 5.3) – A vulnerability through the setup part between set up and the primary administrator login that permits distant attackers to use the default credentials to achieve admin management
  • CVE-2025-57790 (CVSS rating: 8.7) – A path traversal vulnerability that permits distant attackers to carry out unauthorized file system entry via a path traversal concern, leading to distant code execution
  • CVE-2025-57791 (CVSS rating: 6.9) – A vulnerability that permits distant attackers to inject or manipulate command-line arguments handed to inside elements because of inadequate enter validation, leading to a legitimate person session for a low-privilege function
Identity Security Risk Assessment

watchTowr Labs researchers Sonny Macdonald and Piotr Bazydlo have been credited with discovering and reporting the 4 safety defects in April 2025. All of the flagged vulnerabilities have been resolved in variations 11.32.102 and 11.36.60. Commvault SaaS answer isn’t affected.

In an evaluation revealed Wednesday, the cybersecurity firm mentioned risk actors might trend these vulnerabilities into two pre-authenticated exploit chains to realize code execution on vulnerable cases: One that mixes CVE-2025-57791 and CVE-2025-57790, and the opposite that strings CVE-2025-57788, CVE-2025-57789, and CVE-2025-57790.

It is price noting that the second pre-auth distant code execution chain turns into profitable provided that the built-in admin password hasn’t been modified since set up.

The disclosure comes practically 4 months after watchTowr Labs reported a crucial Commvault Command Heart flaw (CVE-2025-34028, CVSS rating: 10.0) that would enable arbitrary code execution on affected installations.

A month later, the U.S. Cybersecurity and Infrastructure Safety Company (CISA) added the vulnerability to its Recognized Exploited Vulnerabilities (KEV) catalog, citing proof of lively exploitation within the wild.

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the most recent breakthroughs, get unique updates, and join with a world community of future-focused thinkers.
Unlock tomorrow’s developments at the moment: learn extra, subscribe to our e-newsletter, and develop into a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Google Fixes Two Chrome Zero-Days Exploited within the Wild Affecting Skia and V8

March 13, 2026

Six Android Malware Households Goal Pix Funds, Banking Apps, and Crypto Wallets

March 13, 2026

Apple Points Safety Updates for Older iOS Units Focused by Coruna WebKit Exploit

March 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

11 Billion Transactions and 26% Exclusion: The Infrastructure Hole the CBN Desires to Shut

By NextTechMarch 13, 2026

With 11 billion funds processed and a clear-eyed view of who nonetheless sits exterior the…

Microsoft newest within the Large Tech race for AI well being instruments

March 13, 2026

Commodities Report: Gold pauses above USD 5000 as vitality shock clouds the worldwide outlook – Insights from Saxo Financial institution

March 13, 2026
Top Trending

11 Billion Transactions and 26% Exclusion: The Infrastructure Hole the CBN Desires to Shut

By NextTechMarch 13, 2026

With 11 billion funds processed and a clear-eyed view of who nonetheless…

Microsoft newest within the Large Tech race for AI well being instruments

By NextTechMarch 13, 2026

Copilot Well being analyses well being information, historical past and wearable knowledge…

Commodities Report: Gold pauses above USD 5000 as vitality shock clouds the worldwide outlook – Insights from Saxo Financial institution

By NextTechMarch 13, 2026

Gold has struggled considerably in current weeks whilst darkish clouds collect over…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!