CVE-2025-40629
HIGHPNETLab 4.2.10 - Path Traversal
Title source: llmDescription
PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform directory traversal by manipulating file paths in HTTP requests. Specifically, the application is vulnerable to requests that access sensitive files outside the intended directory.
Exploits (2)
github
WORKING POC
2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-40629
Scores
CVSS v4
8.7
EPSS
0.0158
EPSS Percentile
81.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Details
CWE
CWE-22
Status
published
Products (1)
PNETLab/PNETLab
4.2.10
Published
May 16, 2025
Tracked Since
Feb 18, 2026