CVE-2025-29902

Published Jun 13, 2025

Last updated 4 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-29902 is identified as a remote code execution vulnerability impacting the Apache HTTP Server. This flaw enables unauthorized individuals to execute arbitrary code directly on the affected server machine. The vulnerability is categorized under CWE-94, which refers to "Improper Control of Generation of Code ('Code Injection')". This indicates that the product constructs code segments using external input without properly neutralizing special elements that could alter the code's syntax or behavior.

Description
Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.
Source
psirt@bosch.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@bosch.com
CWE-94

Social media

Hype score
Not currently trending

References

Sources include official advisories and independent security research.