CVE-2025-2264

HIGH EXPLOITED NUCLEI

Sante PACS Server Path Traversal (CVE-2025-2264)

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2025-2264 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Michael Heinzl, Tenable, including a Metasploit module auxiliary/gather/pacsserver_traversal. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits a path traversal vulnerability (CVE-2025-2264) in Sante PACS Server <= v4.1.0 to retrieve arbitrary files from the system. It sends a crafted HTTP GET request with traversal sequences to access files outside the intended directory.

Description

A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.

Exploits (1)

metasploit WORKING POC
by Michael Heinzl, Tenable · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/pacsserver_traversal.rb

This Metasploit module exploits a path traversal vulnerability (CVE-2025-2264) in Sante PACS Server <= v4.1.0 to retrieve arbitrary files from the system. It sends a crafted HTTP GET request with traversal sequences to access files outside the intended directory.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Sante PACS Server <= v4.1.0
No auth needed
Prerequisites: Network access to the target server · Sante PACS Server running on port 3000 (default)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Sante PACS Server.exe - Path Traversal Information Disclosure
HIGHVERIFIEDby DhiyaneshDK
Shodan: http.favicon.hash:1185161484

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.6437
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2025-07-31
CWE
CWE-22
Status published
Products (1)
santesoft/sante_pacs_server 4.1.0
Published Mar 13, 2025
Tracked Since Feb 18, 2026