CVE-2025-10669

MEDIUM

Airsonic-Advanced <10.6.0 - Unrestricted Upload

Title source: llm
STIX 2.1

Description

A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component Playlist Upload Handler. Performing manipulation results in unrestricted upload. It is possible to initiate the attack remotely. The exploit is now public and may be used.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry
https://vuldb.com/?id.324790
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.324790
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.652356

Scores

CVSS v3 6.3
EPSS 0.0004
EPSS Percentile 12.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-434
Status published
Products (7)
n/a/Airsonic-Advanced 10.0
n/a/Airsonic-Advanced 10.1
n/a/Airsonic-Advanced 10.2
n/a/Airsonic-Advanced 10.3
n/a/Airsonic-Advanced 10.4
n/a/Airsonic-Advanced 10.5
n/a/Airsonic-Advanced 10.6.0
Published Sep 18, 2025
Tracked Since Feb 18, 2026