rootpwn

medium · CVSS v3 6.3 · CVSS v4 5.3 · EPSS 0.00427

CVE-2026-95930

A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the fu…

Description

A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading to version reward-1575 addresses this issue. The identifier of the patch is 45ee5fb647e9894e73b0d7720fa94a66e4540bbb. The affected component should be upgraded.

Scores

Severity
medium
CVSS v2
6.5
CVSS v3
6.3
CVSS v4
5.3
EPSS
0.00427

← All CVEs