CVE-2025-10203

EUVD-2025-29220
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file.  This vulnerability affects Digilent WaveForms 3.24.3 and prior versions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NICNA
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H