info: name: ABB Cylon Aspect 3.08.04- Remote Code Execution author: vijay-sutar severity: critical description: | ABB Cylon Aspect version 3.08.04 is vulnerable to an unauthenticated remote code execution via the DeploySource servlet. It allows an attacker to write arbitrary PHP files using directory traversal in the filename parameter with a special Host header. reference: - https://www.zeroscience.mk/en/vulnerabilities/ZSL-2025-5954.php - https://nvd.nist.gov/vuln/detail/CVE-2025-5954 tags: cve,abb,rce,file-upload,traversal,iot,scada metadata: max-request:1 shodan-query: http.html:"AspectFT" verified:true