Medium severity5.3NVD Advisory· Published May 19, 2025· Updated Jun 17, 2026
CVE-2025-4905
CVE-2025-4905
Description
A vulnerability was found in iop-apl-uw basestation3 up to 3.0.4 and classified as problematic. This issue affects the function load_qc_pickl of the file basestation3/QC.py. The manipulation of the argument qc_file leads to deserialization. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The code maintainer tagged the issue as closed. But there is no new commit nor release in the GitHub repository available so far.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:washington:basestation:*:*:*:*:*:*:*:*Range: >=3.0.0,<=3.0.4
<=3.0.4+ 1 more
- (no CPE)range: <=3.0.4
- (no CPE)range: 3.0.0
Patches
Vulnerability mechanics
References
6- github.com/iop-apl-uw/basestation3/issues/6nvdExploitIssue Tracking
- github.com/iop-apl-uw/basestation3/issues/6nvdExploitIssue Tracking
- github.com/iop-apl-uw/basestation3/issues/6nvdExploitIssue Tracking
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.