9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauthenticated remote attacker can supply traversal sequences via the filename parameter to read and delete arbitrary files. Successful exploitation can disclose sensitive information and delete critical system files, resulting in data loss and potential system compromise or denial of service.
Basic Information
ID
CVE-2026-25069
Source
VulnCheck
Published
Jan 31, 2026 at 23:46
Affected Product
Vendor
SunFounder
Product
Pironman Dashboard (pm_dashboard)
Affected Versions
SunFounder Pironman Dashboard (pm_dashboard) 0