CVE-2025-63414

CRITICAL

Allsky WebUI v2024.12.06_06 - Path Traversal

Title source: llm
STIX 2.1

Description

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP request to the /html/execute.php endpoint with a malicious payload in the id parameter, an attacker can execute arbitrary commands on the underlying operating system, leading to full remote code execution (RCE).

Scores

CVSS v3 10.0
EPSS 0.0162
EPSS Percentile 73.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-22 CWE-78
Status published
Products (1)
allskyteam/allsky 2024.12.06_06
Published Dec 16, 2025
Tracked Since Feb 18, 2026