- Description
 - In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.
 - Source
 - cve@mitre.org
 - NVD status
 - Analyzed
 - Products
 - oxidized_web
 
CVSS 3.1
- Type
 - Primary
 - Base score
 - 9.8
 - Impact score
 - 5.9
 - Exploitability score
 - 3.9
 - Vector string
 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
 - Severity
 - CRITICAL
 
- cve@mitre.org
 - CWE-22
 - nvd@nist.gov
 - NVD-CWE-noinfo
 
- Hype score
 - Not currently trending
 
📢 New blog post published! "CVE-2025-27590: Arbitrary File Write to Remote Code Execution in Oxidized Web" https://t.co/lzpUkvgbpf
@devoo1337
31 May 2025
458 Impressions
1 Retweet
15 Likes
1 Bookmark
0 Replies
0 Quotes
🔴 Oxidized Web, Unauthenticated Remote Code Execution, #CVE-2025-27590 (Critical) https://t.co/5nCFJfixlv
@dailycve
10 Mar 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27590 (CVSS:9.0, CRITICAL) is Undergoing Analysis. In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr..https://t.co/xVvoq83Sgv #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
8 Mar 2025
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27590 (CVSS:9.0, CRITICAL) is Awaiting Analysis. In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain contr..https://t.co/xVvoq83Sgv #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
7 Mar 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-27590 ⚠️🔴 CRITICAL (9) 🏢 Oxidized Web project - Oxidized Web 🏗️ 0 🔗 https://t.co/7mrg5UmDks 🔗 https://t.co/DOTskiqUG1 #CyberCron #VulnAlert #InfoSec https://t.co/RcMQq3oQqm
@cybercronai
4 Mar 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27590 In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running… https://t.co/cPAF8XXvDB
@CVEnew
3 Mar 2025
87 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-27590: CRITICAL] In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.#cybersecurity,#vulnerability https://t.co/QdqVwjGCFp https://t.co/POC8ii
@CveFindCom
3 Mar 2025
51 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:a:oxidized_web_project:oxidized_web:*:*:*:*:*:oxidized:*:*",
            "vulnerable": true,
            "matchCriteriaId": "B1A269F6-50B5-44CE-BD9F-8A03BE259152",
            "versionEndExcluding": "0.15.0"
          }
        ],
        "operator": "OR"
      }
    ]
  }
]