CVE-2025-25371

HIGH

NASA cFS Aquila - Path Traversal in OSAL Module

Title source: llm
STIX 2.1

Description

NASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the system.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0053
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
nasa/cfs aquila
nasa/core_flight_system 6.7.0
Published Mar 25, 2025
Tracked Since Feb 18, 2026