CVE-2025-34121

CRITICAL

Idera Up.Time Monitoring Station <=7.2 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-34121. PoCs published by Metasploit, including Metasploit module exploits/multi/http/uptime_file_upload_1.

AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in Idera Up.Time Monitoring Station 7.0/7.2, allowing unauthenticated attackers to upload and execute PHP payloads via the 'post2file.php' endpoint.

Description

An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code execution as the web server user. NOTE: The bypass for this vulnerability is tracked as CVE-2015-9263.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38732

This Metasploit module exploits an arbitrary file upload vulnerability in Idera Up.Time Monitoring Station 7.0/7.2, allowing unauthenticated attackers to upload and execute PHP payloads via the 'post2file.php' endpoint.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Idera Up.Time Monitoring Station 7.0/7.2
No auth needed
Prerequisites: Network access to the target server · Target running vulnerable version of Up.Time
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/uptime_file_upload_1.rb

This Metasploit module exploits an arbitrary file upload vulnerability in Idera Up.Time Monitoring Station 7.0/7.2, allowing unauthenticated attackers to upload and execute PHP payloads via the `post2file.php` endpoint.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Idera Up.Time Monitoring Station 7.0/7.2
No auth needed
Prerequisites: Network access to the target server · Target running vulnerable version of Up.Time
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 9.3
EPSS 0.0168
EPSS Percentile 73.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306 CWE-434
Status published
Products (1)
Idera/Up.Time Monitoring Station < 7.2
Published Jul 16, 2025
Tracked Since Feb 18, 2026