CVE-2025-27590
CRITICALoxidized-web < 0.15.0 - Unauthenticated Path Traversal
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-27590. PoCs published by fatkz.
AI-analyzed exploit summary This is a functional PoC exploit for CVE-2025-27590, demonstrating command injection via multipart form uploads. It injects an SSH key into the target system's authorized_keys file by exploiting unsanitized form parameters.
Description
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.
Exploits (1)
This is a functional PoC exploit for CVE-2025-27590, demonstrating command injection via multipart form uploads. It injects an SSH key into the target system's authorized_keys file by exploiting unsanitized form parameters.
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H