References https://nvd.nist.gov/vuln/detail/CVE-2025-3943 https://cve.imfht.com/detail/CVE-2025-3943 https://www.sentinelone.com/vulnerability-database/cve-2025-3943/ https://thehackernews.com/2025/07/critical-flaws-in-niagara-framework.html https://www.nozominetworks.com/blog/critical-vulnerabilities-found-in-tridium-niagara-framework https://www.runzero.com/blog/tridium-niagara/ https://www.honeywell.com/content/dam/honeywellbt/en/documents/downloads/product-security/security-notification/hon-corp-niagara-software-vulnerabilities-2025-05-22-01.pdf https://www.cve.org/CVERecord?id=CVE-2025-3943 https://cve.imfht.com/detail/CVE-2025-3943?lang=en https://dbugs.ptsecurity.com/vulnerability/CVE-2025-3943
Related VulnerabilitiesPoCCVE-2026-39352: Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path TraversalPoCfrappe-default-login: Frappe Framework - Default Login CredentialsPoCCVE-2025-41242: Spring Framework - Path TraversalPoCCVE-2024-38819: Spring Framework Path Traversal in Functional Web FrameworksServerless Framework 未授权 命令注入漏洞Astro Web Framework Cloudflare /_image 服务器端请求伪造漏洞(CVE-2025-58179)Spring Framework路径遍历漏洞(CVE-2024-38819)Vmware Spring Framework 逻辑缺陷漏洞OpenOrange Business Framework访问控制错误漏洞(CVE-2024-42048)PoCCVE-2020-0646: Microsoft .NET Framework - Remote Code ExecutionPoCspring4shell-CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+PoCCVE-2016-6601: ZOHO WebNMS Framework <5.2 SP1 - Local File Inclusion