CVE 7.3 HIGH

Zabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0._CVE-2025-27234

7.3 / 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.

Basic Information

ID CVE-2025-27234
Source Zabbix
Published Sep 12, 2025 at 10:31

Affected Product

Vendor Zabbix
Product Zabbix
Version 5.0.0
Affected Versions Zabbix Zabbix 5.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.