CVE-2025-68645
HIGH KEV NUCLEIZimbra Collaboration Suite 10.0.0-10.0.17 - Unauthenticated Local File Inclusion via RestFilter Servlet
Title source: llmExploitation Summary
CVE-2025-68645 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 22, 2026. EIP tracks 8 public exploits from researchers including iSee857, chinaxploiter, HarisAidhin. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a Python script designed to scan for CVE-2025-68645, a local file inclusion vulnerability in Zimbra Collaboration. It checks for the presence of 'context-param' and 'param-value' in the response from '/h/rest?javax.servlet.include.servlet_path=/WEB-INF/web.xml'.
Description
A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.
Exploits (8)
The repository contains a Python script designed to scan for CVE-2025-68645, a local file inclusion vulnerability in Zimbra Collaboration. It checks for the presence of 'context-param' and 'param-value' in the response from '/h/rest?javax.servlet.include.servlet_path=/WEB-INF/web.xml'.
The repository contains obfuscated Python code using PyArmor, which is highly suspicious and indicative of malicious intent. The lack of clear exploit details and the use of obfuscation suggest this is a deceptive payload rather than a legitimate PoC.
The repository contains a Python-based scanner for detecting CVE-2025-68645, a Local File Inclusion (LFI) vulnerability in Zimbra Collaboration Suite. It tests multiple payloads against various endpoints to confirm vulnerability but does not include exploit code for actual file retrieval or further exploitation.
This repository contains a Python-based scanner for detecting CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration Suite via the `/h/printcalendar` endpoint. It tests multiple payloads to identify improper path normalization in the `javax.servlet.include.servlet_path` parameter.
This repository contains a Python-based scanner for detecting CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration Suite via the `/h/printcalendar` endpoint. It tests multiple payloads to identify improper path normalization but does not include exploit code for actual file inclusion.
This repository provides defensive security content for CVE-2025-68645, an LFI vulnerability in Zimbra Classic UI. It includes detection rules, mitigation guidance, and advisory details but explicitly excludes exploit code.
This repository provides a detailed technical analysis of CVE-2025-68645, an LFI vulnerability in Zimbra Collaboration's Webmail Classic UI due to improper input validation in the RestFilter servlet. It includes a PoC request, affected versions, remediation steps, and references.
Nuclei Templates (1)
http.title:"Zimbra Collaboration Suite"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H