CVE-2025-61168
Critical · CVSS 9.8SIGB PMB — PHP Object Deserialization RCE (CWE-502)
- CVSS
- 9.8
- nvd
- EPSS
- 0.47%
- 37th pct
- KEV
- No
- Class
- other
- CWE-502
Description
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
Search profile — drives PoC discovery
Symbols cms_rest.phpunserializecms_restPMBv8.0.1.14
Keywords CVE-2025-61168PMB cms_rest.php unserializeSIGB PMB deserialization RCEPMB 8.0.1.14 arbitrary code executionPMB CMS REST PHP object injection
Versions: ≤ 8.0.1.14
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z