seclists.org
http://seclists.org/fulldisclosure/2025/Jul/18 CVE-2025-54768
MEDIUM
KL-001-2025-015: Xorux LPAR2RRD Read Only User Log Download Exposing Sensitive Information
Record summary
CVE-2025-54768 has a selected CVSS score of 5.3 (medium).
Description
An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to download logs from the appliance configuration, exposing sensitive information.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
LPAR2RRDBrowse Xorux / LPAR2RRDDefault status: affected | CVE List | 8.04 | affected |
References
4korelogic.comThird-party advisory
https://korelogic.com/Resources/Advisories/KL-001-2025-015.txt lpar2rrd.comrelease notes
https://lpar2rrd.com/note800.php nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-54768