Multiple critical vulnerabilities in D.O.S SS1 asset management tool allow remote…
Multiple critical vulnerabilities in D.O.S SS1 asset management tool allow remote attackers to gain unauthorized access and execute arbitrary commands with elevated privileges.
株式会社ディー・オー・エス (D.O.S Corporation) has disclosed eight vulnerabilities affecting their SS1 asset management tool. The vulnerabilities include insufficient cryptographic strength (CVE-2025-46409), externally accessible files/directories (CVE-2025-52460), improper access control on critical resources (CVE-2025-53396), insufficient file upload validation (CVE-2025-53970, CVE-2025-54762), path traversal (CVE-2025-54819, CVE-2025-58072), and hardcoded password usage (CVE-2025-58081).
Exploitation of these vulnerabilities could allow remote unauthenticated attackers to access authenticated functions, read uploaded files and configuration data, overwrite legitimate files, and view arbitrary files. Local users with client terminal access could escalate privileges to root or SYSTEM level and execute arbitrary OS commands. The most severe vulnerabilities (CVE-2025-53970, CVE-2025-54762) carry CVSS v3 scores of 9.8. Some vulnerabilities affect only Windows environments while others impact only macOS deployments.
Affected versions include SS1 Ver.16.0.0.10 and earlier (media version 16.0.0a and earlier) and SS1 Cloud Ver.2.1.3 and earlier. Users are advised to update to the latest version immediately according to vendor guidance published through IPA Japan and JVN.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/20250827-jvn.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free