U.S. CISA adds Google Chromium, DrayTek routers, and SAP NetWeaver flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-12987 | OS Command Injection in DrayTek Vigor2960/300B Web Interface CVE-2024-12987 is an OS command injection flaw in the web management interface of DrayTek Vigor2960 and Vigor300B routers running firmware 1.5.1.4. An unauthenticated remote attacker triggers it by sending a crafted request to the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint with a manipulated 'session' parameter, which is passed to the underlying operating system without proper sanitization (CWE-77/CWE-78). Successful exploitation yields arbitrary operating-system command execution on the router, which can mean full device compromise and a foothold for pivoting into the protected network. Any organization running affected firmware on these models is exposed, especially sites where the management interface is reachable from the internet. Exploitation is confirmed in the wild: a public proof-of-concept is available, EPSS assigns a 98.1% probability of exploitation within 30 days (100th percentile), and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-15, requiring federal remediation under BOD 22-01. Do: Upgrade Vigor2960 and Vigor300B units from firmware 1.5.1.4 to version 1.5.1.5 or later. Until patched, restrict internet-facing access to the web management interface and review device logs for suspicious requests to /cgi-bin/mainfunction.cgi/apmcfgupload containing anomalous session parameters. Because the flaw is in CISA's KEV catalog, federal agencies must apply the vendor fix or applicable BOD 22-01 mitigations by the required deadline. | 6.9 | 98% | KEV PoC |
| largeplausibly tens of thousands of internet-exposed devices | |
| CVE-2025-42999 | Insecure Deserialization in SAP NetWeaver Visual Composer Metadata Uploader CVE-2025-42999 is an insecure deserialization flaw (CWE-502) in the Visual Composer Metadata Uploader component of SAP NetWeaver. It is triggered when a privileged user uploads untrusted or malicious content to the Metadata Uploader, which the application then deserializes; on its own the flaw requires high-privilege access, but attackers commonly chain it with the separately tracked unauthenticated upload flaw CVE-2025-31324 in the same component. Successful exploitation can yield remote code execution and full compromise of the host's confidentiality, integrity, and availability, with impact beyond the vulnerable component (CVSS scope changed, 9.1 critical). Any organization running SAP NetWeaver with the Visual Composer Metadata Uploader enabled, especially internet-facing application servers, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-15 with known ransomware use, and reporting links active attacks to ransomware groups (BianLian and RansomExx deploying the PipeMagic trojan) and to Chinese-linked APTs exploiting the sibling CVE-2025-31324. Do: Apply SAP's security patches addressing CVE-2025-42999 together with the companion CVE-2025-31324 in the same Visual Composer Metadata Uploader, per vendor instructions, or restrict/disable access to the Metadata Uploader endpoint if patching is delayed. Given confirmed ransomware use (BianLian, RansomExx) and PipeMagic trojan deployments, review upload and authentication logs on NetWeaver servers and hunt for signs of compromise and post-exploitation activity. U.S. federal agencies must follow CISA BOD 22-01 guidance: apply mitigations by the KEV remediation due date or discontinue use of affected instances. | 9.1 | 14% | KEV ransomware PoC |
| moderatelow thousands of internet-exposed SAP NetWeaver servers (≈1k–10k systems), with a substantially larger internal install base | |
| CVE-2025-4664 | Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) NVD description · AI analysis pending | 4.3 | 6% |
| — |
Full article295 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium, DrayTek routers, and SAP NetWeaver flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chromium, DrayTek routers, and SAP NetWeaver flaws to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the descriptions for these flaws:
- CVE-2024-12987 (CVSS score of 7.3) DrayTek Vigor Routers OS Command Injection Vulnerability – A critical OS command injection flaw in DrayTek Vigor2960 and Vigor300B (v1.5.1.4) via the Web UI allows remote attacks through the
sessionparameter. - CVE-2025-4664 (CVSS score of 4.3) Google Chromium Loader Insufficient Policy Enforcement Vulnerability – This week Google released emergency security updates to address a Chrome browser vulnerability, tracked as CVE-2025-4664, that could lead to full account takeover. The security researcher Vsevolod Kokorin (@slonser_) discovered the vulnerability, which stems from an insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113. A remote attacker could trigger the flaw to leak cross-origin data via a crafted HTML page. Google warned of the availability of a public exploit for this high-severity flaw.
- CVE-2025-42999 (CVSS score of 9.1) SAP NetWeaver Deserialization Vulnerability – SAP NetWeaver Visual Composer has a flaw allowing privileged users to upload malicious content, risking system confidentiality, integrity, and availability.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by June 5, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/177962/hacking/u-s-cisa-adds-google-chromium-draytek-routers-and-sap-netweaver-flaws-to-its-known-exploited-vulnerabilities-catalog.html