CVE-2025-2776
CRITICAL KEV NUCLEISysAid On-Prem <= 23.3.40 - XML External Entity
Title source: nucleiDescription
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
Exploits (2)
github
WORKING POC
12 stars
by watchtowrlabs · pythonremote
https://github.com/watchtowrlabs/watchTowr-vs-SysAid-PreAuth-RCE-Chain
nomisec
WRITEUP
by mrk336 · poc
https://github.com/mrk336/From-EternalBlue-to-CVE-2025-2776-The-Evolution-of-an-SMB-Attack
Nuclei Templates (1)
SysAid On-Prem <= 23.3.40 - XML External Entity
CRITICALby johnk3r
Shodan:
http.favicon.hash:"1540720428"
FOFA:
icon_hash=1540720428
Scores
CVSS v3
9.3
EPSS
0.6260
EPSS Percentile
98.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Details
CISA KEV
2025-07-22
VulnCheck KEV
2025-05-14
ENISA EUVD
EUVD-2025-13875
CWE
CWE-611
Status
published
Products (1)
sysaid/sysaid
< 23.3.40
Published
May 07, 2025
KEV Added
Jul 22, 2025
Tracked Since
Feb 18, 2026