CVE-2020-35370

HIGH

raysync < 3.3.3.8 - Unauthenticated Remote Code Execution via Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-35370. PoCs published by james.

AI-analyzed exploit summary This exploit leverages a path traversal vulnerability in Raysync to overwrite the remote manage.db file, allowing an attacker to reset the admin password and gain unauthorized access. Arbitrary command execution is achieved by modifying the RaySyncServer.sh script and triggering a reset.

Description

A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as "admin", then to modify specific shell file to achieve remote code execution(RCE) on the hosting server.

Exploits (1)

exploitdb WORKING POC
by james · textwebappslinux
https://www.exploit-db.com/exploits/49265

This exploit leverages a path traversal vulnerability in Raysync to overwrite the remote manage.db file, allowing an attacker to reset the admin password and gain unauthorized access. Arbitrary command execution is achieved by modifying the RaySyncServer.sh script and triggering a reset.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Raysync below 3.3.3.8
No auth needed
Prerequisites: Access to the Raysync server · Ability to send HTTP requests to the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/49265

Scores

CVSS v3 8.8
EPSS 0.0747
EPSS Percentile 93.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
raysync/raysync < 3.3.3.8
Published Dec 23, 2020
Tracked Since Feb 18, 2026