CVE-2025-2777

CRITICAL EXPLOITED NUCLEI

SysAid On-Prem <= 23.3.40 - XML External Entity

Title source: nuclei

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.

Exploits (1)

github WORKING POC 12 stars
by watchtowrlabs · pythonremote
https://github.com/watchtowrlabs/watchTowr-vs-SysAid-PreAuth-RCE-Chain

Nuclei Templates (1)

SysAid On-Prem <= 23.3.40 - XML External Entity
CRITICALby johnk3r
Shodan: http.favicon.hash:"1540720428"
FOFA: icon_hash=1540720428

Scores

CVSS v3 9.3
EPSS 0.2311
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Details

VulnCheck KEV 2025-05-14
CWE
CWE-611
Status published
Products (1)
sysaid/sysaid < 23.3.40
Published May 07, 2025
Tracked Since Feb 18, 2026