VYPR
High severityNVD Advisory· Published Mar 2, 2026· Updated Apr 27, 2026

CVE-2025-10350

CVE-2025-10350

Description

SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An SQL injection vulnerability in the CGM NETRAAD PACS imageserver module allows an authenticated attacker to access the database, including data processed by CGM CLININET.

Root

Cause The CGM NETRAAD software, a PACS and RIS system for medical imaging, contains an SQL injection vulnerability in its imageserver module when processing DICOM C-FIND queries. The software fails to properly neutralize special elements used in SQL commands, allowing an attacker to inject arbitrary SQL statements [1]. This vulnerability affects all versions before 7.9.0 [1].

Exploitation

An attacker must be connected to the PACS network as an authenticated user to exploit this flaw. By crafting a malicious C-FIND query with embedded SQL code, the attacker can manipulate database queries processed by the imageserver module [1]. The vulnerability does not require prior local access, but does require network-level authentication to the PACS service.

Impact

Successful exploitation grants the attacker read access to the underlying database. This includes exposure of patient data and other information processed by the related CGM CLININET software, which may include sensitive medical records. The attacker could also potentially extract or alter data, depending on database permissions [1].

Mitigation

The vendor has addressed this issue in version 7.9.0 of CGM NETRAAD. Users are advised to upgrade to this version or later to remediate the vulnerability. No other workarounds have been publicly documented [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.