CVE-2025-2776
CRITICAL KEV NUCLEISysAid On-Prem <= 23.3.40 - XML External Entity
Title source: nucleiExploitation Summary
CVE-2025-2776 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2025. EIP tracks 2 public exploits from researchers including watchtowrlabs, mrk336. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit PoC for a pre-authentication RCE chain in SysAid (CVE-2025-2776). The exploit leverages XXE to leak credentials and then executes arbitrary commands via API endpoint manipulation.
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.
Exploits (2)
This repository contains a functional exploit PoC for a pre-authentication RCE chain in SysAid (CVE-2025-2776). The exploit leverages XXE to leak credentials and then executes arbitrary commands via API endpoint manipulation.
This repository provides a detailed writeup and detection strategies for CVE-2025-2776, an SMB-based attack evolving from EternalBlue. It includes PowerShell-based reverse shell techniques and KQL queries for detection.
Nuclei Templates (1)
http.favicon.hash:"1540720428"
icon_hash=1540720428
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L