# SS1 asset management tool has 8 critical flaws

Published: 2025-08-26 · Severity: high
Canonical: https://vorant.io/reports/30127bc3-8966-51f2-86ae-1ef1c197c373/ss1-asset-management-tool-has-8-critical-flaws

> D.O.S Corporation's SS1 asset management tool contains eight vulnerabilities including weak crypto, path traversal, and hardcoded passwords enabling remote access and privilege escalation.

Japan's IPA has disclosed eight vulnerabilities in SS1, an asset management tool from D.O.S Corporation. The flaws span weak cryptography (CVE-2025-46409), externally accessible files (CVE-2025-52460), improper access control (CVE-2025-53396), insufficient file upload validation (CVE-2025-53970, CVE-2025-54762), path traversal (CVE-2025-54819, CVE-2025-58072), and hardcoded passwords (CVE-2025-58081).

Exploitation could allow remote unauthenticated attackers to access authenticated functions, read uploaded files and configuration data, overwrite legitimate files, or view arbitrary files with root privileges. Local authenticated users could escalate to root or SYSTEM privileges and execute arbitrary OS commands. The vendor notes that certain vulnerabilities affect only Windows (CVE-2025-52460, CVE-2025-53970, CVE-2025-54762) or macOS (CVE-2025-53396, CVE-2025-58072, CVE-2025-58081) deployments.

Affected versions include SS1 Ver.16.0.0.10 and earlier (media version 16.0.0a and earlier) and SS1 Cloud Ver.2.1.3 and earlier. The vendor has released patches and urges immediate updates.

## Mentioned in this report

- Vulnerabilities: CVE-2025-46409, CVE-2025-52460, CVE-2025-53396, CVE-2025-53970, CVE-2025-54762, CVE-2025-54819, CVE-2025-58072, CVE-2025-58081

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20250827-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/30127bc3-8966-51f2-86ae-1ef1c197c373/ss1-asset-management-tool-has-8-critical-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
