LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-60237

CVE-2025-60237 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 19, 2026

Themeton Finag - Insecure Deserialization

Published: March 19, 2026Updated: March 19, 2026Remote Exploitable

Overview

Themeton Finag <= 1.5.0 contains an insecure deserialization vulnerability caused by deserialization of untrusted data, letting attackers perform object injection remotely, exploit requires crafted input.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary code or manipulate application logic via object injection.

Mitigation

Update to the latest version beyond 1.5.0.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 19, 2026

šŸ”“ CVE-2025-60237 - Critical (9.8) Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-60237/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 19, 2026

šŸ”“ CVE-2025-60237 - Critical (9.8) Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from n/a through 1.5.0. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2025-60237/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2025-60237
Severity
Critical
CVSS Score
9.8
Type
insecure_deserialization
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-502

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days