CVE-2025-2776

CRITICAL KEV NUCLEI

SysAid On-Prem <= 23.3.40 - XML External Entity

Title source: nuclei

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

Exploits (2)

github WORKING POC 12 stars
by watchtowrlabs · pythonremote
https://github.com/watchtowrlabs/watchTowr-vs-SysAid-PreAuth-RCE-Chain
nomisec WRITEUP
by mrk336 · poc
https://github.com/mrk336/From-EternalBlue-to-CVE-2025-2776-The-Evolution-of-an-SMB-Attack

Nuclei Templates (1)

SysAid On-Prem <= 23.3.40 - XML External Entity
CRITICALby johnk3r
Shodan: http.favicon.hash:"1540720428"
FOFA: icon_hash=1540720428

Scores

CVSS v3 9.3
EPSS 0.6260
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Details

CISA KEV 2025-07-22
VulnCheck KEV 2025-05-14
ENISA EUVD EUVD-2025-13875
CWE
CWE-611
Status published
Products (1)
sysaid/sysaid < 23.3.40
Published May 07, 2025
KEV Added Jul 22, 2025
Tracked Since Feb 18, 2026