CVE-2025-9401Utcms_project · Utcms
Vulnerability data via NVD (ingested)
A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-frame/admin/login.php of the component Login. Such manipulation of the argument code leads to incorrect comparison. The attack can be executed remotely. The attack requires a high level of complexity. It is stated that the exploitability is difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2025-9401product:"Utcms Project Utcms" version:"9.0"http.html:"Utcms"More intel sources (5)
vuln:CVE-2025-9401vulnerabilities.cve_id: CVE-2025-9401CVE-2025-9401CVE-2025-9401"CVE-2025-9401" exploit -site:nvd.nist.gov