CVE-2025-60595
8.2SPH Engineering · UgCS
SPH Engineering UgCS version 5.13.0 contains a vulnerability that allows for arbitrary code execution by an unauthenticated attacker.
Executive summary
A critical arbitrary code execution vulnerability in SPH Engineering UgCS 5.13.0 poses a severe risk to system integrity and may allow complete unauthorized control.
Vulnerability
This vulnerability is an arbitrary code execution flaw that can be triggered by an unauthenticated, remote attacker over the network. The vulnerability allows an attacker to execute unauthorized commands without requiring any prior system access or user interaction.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the host system, which could lead to full system compromise. Given the CVSS score of 8.2, this represents a high-severity risk that could result in unauthorized data access, the deployment of malicious software, or the complete loss of availability for the drone flight management platform.
Remediation
Immediate Action: Users should restrict network access to the UgCS application and monitor the vendor website for the release of an official security patch to address the code execution flaw.
Proactive Monitoring: Security teams should monitor network traffic for suspicious inbound requests to the UgCS service and review system logs for unexpected process execution.
Compensating Controls: Implement a Web Application Firewall or network-based access control lists to restrict traffic to the UgCS management interface to trusted IP addresses only.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists on GitHub (referenced via the CVE program).
Analyst recommendation
The presence of an arbitrary code execution vulnerability in a flight management system presents a high risk to operational security. Administrators should prioritize isolating affected instances from untrusted networks immediately. Organizations must remain vigilant for vendor-supplied patches and apply them as soon as they become available to remediate this critical exposure.