8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.
Basic Information
ID
CVE-2025-54769
Source
KoreLogic
Published
Jul 28, 2025 at 23:34
Modified
Jul 29, 2025 at 13:22
Affected Product
Vendor
Xorux
Product
LPAR2RRD
Version
8.04
Affected Versions
Xorux LPAR2RRD 8.04