CVE-2025-2777

CRITICAL EXPLOITED NUCLEI

SysAid On-Prem <= 23.3.40 - XML External Entity

Title source: nuclei
STIX 2.1

Exploitation Summary

CVE-2025-2777 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including watchtowrlabs. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional exploit PoC for a pre-authentication RCE chain in SysAid (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778). The exploit leverages XXE to leak credentials and then executes arbitrary commands via API endpoint manipulation.

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.

Exploits (1)

github WORKING POC 12 stars
by watchtowrlabs · pythonremote
https://github.com/watchtowrlabs/watchTowr-vs-SysAid-PreAuth-RCE-Chain

This repository contains a functional exploit PoC for a pre-authentication RCE chain in SysAid (CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778). The exploit leverages XXE to leak credentials and then executes arbitrary commands via API endpoint manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SysAid <= 23.3.40
No auth needed
Prerequisites: Network access to the target SysAid server · Python environment with 'requests' library
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

SysAid On-Prem <= 23.3.40 - XML External Entity
CRITICALby johnk3r
Shodan: http.favicon.hash:"1540720428"
FOFA: icon_hash=1540720428

References (2)

Core 2
Core References
Release Notes vendor-advisory
https://documentation.sysaid.com/docs/24-40-60

Scores

CVSS v3 9.3
EPSS 0.2311
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2025-05-14
CWE
CWE-611
Status published
Products (1)
sysaid/sysaid < 23.3.40
Published May 07, 2025
Tracked Since Feb 18, 2026