ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands as the web server user. Attackers can upload PHP executable files via the Quick File Uploader page, resulting in remote code execution on the server.
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityLow
RequirementsNone
PrivilegesNone
User InteractionNone
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | cve.org | initial, patch: Unavailable | 8.1 |
Affected Software
| Vendor | Product | Version |
|---|
| ReQuest Serious Play LLC | ReQuest Serious Play | 2.0.1.823 |
| ReQuest Serious Play LLC | ReQuest Serious Play | 6.3.2.4203 |
| ReQuest Serious Play LLC | ReQuest Serious Play | 6.4.2.4681 |
| ReQuest Serious Play LLC | ReQuest Serious Play | 6.5.2.4954 |
| ReQuest Serious Play LLC | ReQuest Serious Play | 7.0.2.4954 |
| ReQuest Serious Play LLC | ReQuest Serious Play Pro | 7.0.3.4968 |
Published: 2025-12-05