CVE-2025-1546 | BDCOM Behavior Management and Auditing System up to 20250210 operate.mds log_operate_clear start_code os command injection
A vulnerability described as critical has been identified in BDCOM Behavior Management and Auditing System up to 20250210. The impacted element is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code results in os command injection.
This vulnerability is known as CVE-2025-1546. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.