CVE-2025-54769

HIGH

Xorux Lpar2rrd < 8.04 - Remote Code Execution

Title source: rule

Description

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

Exploits (2)

exploitdb WORKING POC
by Byte Reaper · cwebappsmultiple
https://www.exploit-db.com/exploits/52391
nomisec WORKING POC 2 stars
by byteReaper77 · poc
https://github.com/byteReaper77/CVE-2025-54769

Scores

CVSS v3 8.8
EPSS 0.0612
EPSS Percentile 90.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-648 CWE-434 CWE-24
Status published
Products (1)
xorux/lpar2rrd < 8.04
Published Jul 29, 2025
Tracked Since Feb 18, 2026