Record summary

CVE-2019-25480 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to write executable code to the web root and achieve remote code execution.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List*affected

Proofs of concept

1

Catalogued exploits

ExploitDBARMBot Botnet - Arbitrary Code ExecutionExploitDB exploitby prsecurityNot analyzed1 file
ExploitDB

PoC details

References

4