Impact
The vulnerability arises from deserializing untrusted data in eta‑otp‑lock, allowing object injection that can lead to remote code execution. This is a classic case of insecure deserialization (CWE‑502) and can compromise confidentiality, integrity, and availability if an attacker can supply malicious input.
Affected Systems
Affected products include TUBITAK BILGEM Software Technologies Research Institute’s eta‑otp‑lock versions prior to 1.0.4. Versions 1.0.4 and later contain the fix and should be applied.
Risk and Exploitability
The CVSS score of 7.8 reflects high severity; no EPSS score is available, so we cannot quantify exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote deserialization of data sent over the network or by local users with write access to the application’s data store.
OpenCVE Enrichment