CVE-2020-25068

HIGH

Setelsa Conacwin v3.7.1.2 - Unauthenticated Local File Inclusion via Directory Traversal URI

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-25068. PoCs published by bryanroma.

AI-analyzed exploit summary This is a Python-based exploit for CVE-2020-25068, targeting a local file inclusion (LFI) vulnerability in Setelsa Conacwin v3.7.1.2. The exploit allows unauthenticated remote attackers to read arbitrary files on the server via directory traversal sequences.

Description

Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer indicated that the affected version does not exist. Furthermore, they indicated that they detected this problem in an internal audit more than 3 years ago and fixed it in 2017.

Exploits (1)

nomisec WORKING POC
by bryanroma · poc
https://github.com/bryanroma/CVE-2020-25068

This is a Python-based exploit for CVE-2020-25068, targeting a local file inclusion (LFI) vulnerability in Setelsa Conacwin v3.7.1.2. The exploit allows unauthenticated remote attackers to read arbitrary files on the server via directory traversal sequences.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Setelsa Conacwin v3.7.1.2
No auth needed
Prerequisites: Network access to the target server · Conacwin v3.7.1.2 running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=CLAHE0qUHXs
Third Party Advisory x_refsource_misc
https://github.com/bryanroma/CVE-2020-25068

Scores

CVSS v3 7.5
EPSS 0.0390
EPSS Percentile 88.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
setelsa-security/conacwin 3.7.1.2
Published Sep 03, 2020
Tracked Since Feb 18, 2026