CVE-2025-14988
CWE-732Published: January 27, 2026· Updated: Jun 17, 2026
Official Description
A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.
Risk Analysis
ibaPDA contains a security flaw that permits unauthorized file system actions, potentially compromising the system's confidentiality, integrity, and availability. The critical CVSS score of 10.0 indicates the highest level of urgency for remediation.
No public exploit is known, and the vulnerability is not in the KEV. It is remotely exploitable with low attack complexity.
Consult the vendor for available security updates or patches to address this file system vulnerability.
Technical Analysis
CVE-2025-14988 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.
The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.
CVSS v3.1 Vector Breakdown
Exploit & PoC Resources
All References (1)
Quick Facts
Related CVEs (CWE-732)
Recommended Actions
- →Apply vendor patches immediately
- →Monitor CVE-2025-14988 in threat intel feeds
- →Review IDS/IPS signatures for exploitation attempts