CVE-2025-10870

Publication date

2025-11-07 09:26:39

Family

INCIBE

State

PUBLISHED

Description

SQL injection vulnerability in DIALs CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete databases by sending POST and GET requests with the ultralogin parameter in /centrosnet/ultralogin.php.