CVE-2025-34509
HIGH EXPLOITED NUCLEISitecore XP/XM 10.1-10.1.4, 10.2, 10.3-10.3.3, 10.4-10.4.1 - Unauthenticated RCE via Hardcoded Credentials
Title source: llmExploitation Summary
CVE-2025-34509 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 1 public exploit from researchers including Piotr Bazydlo, msutovsky-r7, including a Metasploit module exploits/windows/http/sitecore_xp_cve_2025_34510.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits CVE-2025-34510, a path traversal vulnerability in Sitecore XP, leading to remote code execution. It also leverages CVE-2025-34509 (hardcoded credentials) for authentication.
Description
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974 PRE, all versions of 10.2, 10.3 to 10.3.3 rev. 011967 PRE, and 10.4 to 10.4.1 rev. 011941 PRE contain a hardcoded user account. Unauthenticated and remote attackers can use this account to access administrative API over HTTP.
Exploits (1)
This Metasploit module exploits CVE-2025-34510, a path traversal vulnerability in Sitecore XP, leading to remote code execution. It also leverages CVE-2025-34509 (hardcoded credentials) for authentication.
Nuclei Templates (1)
title:"sitecore"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N