# CVE-2025-14700

## Summary

- **CVE ID:** CVE-2025-14700
- **Severity:** CRITICAL
- **CVSS Score:** 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-1336
- **Published:** Dec 17, 2025
- **Last Modified:** Mar 12, 2026

## Description

An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.

## Affected Products

- Arcadia Technology, LLC — Crafty Controller (4.6.1)

## References

- [CNA](https://gitlab.com/crafty-controller/crafty-4/-/issues/646)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 6.65%
- **EPSS Percentile:** 93.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._