CVE-2025-61582
Unauthenticated denial of service leading to application crash in Ts3 manager <=v2.2.1 .
A denial-of-service vulnerability was identified in TS3 Manager versions 2.2.1 and earlier due to improper handling of specially crafted Unicode input in the login interface. Submitting certain Unicode tag characters to the Server field triggers an unhandled exception during ASCII conversion, causing the application to crash within seconds. The issue is remotely exploitable without authentication or user interaction and results in complete service disruption.
Identifier
CVE-2025-61582
Affected product
TS3 manager
Disclosed
Oct 1, 2025
Credit
Krishna Agarwal, Swapnil Ade
Proof of Concept
- In the
Serverfield, input the unicode tag payload ⁽¹⁾ and fill other fields such as username and password. - click on connect.
Cannot convert name to ASCII and application should get crashed in 4-5 seconds.Remediation
Running this software?
If TS3 manager is in your environment, the reproduction steps above are enough to verify exposure yourself. If you would rather have the same class of bug hunted across your own stack, that is what we do as an engagement.