AI description
CVE-2025-54769 is a directory traversal and file upload vulnerability discovered in Xorux LPAR2RRD, affecting versions up to 8.04. The issue resides in an authenticated file upload endpoint that fails to sanitize user-supplied path components, allowing the use of `../` traversal sequences. Consequently, an authenticated user with read-only privileges can bypass directory restrictions and place uploaded files into arbitrary locations on the host filesystem. Because LPAR2RRD is implemented in Perl, it dynamically loads module files from known directories at runtime. An attacker can exploit this behavior by using the directory traversal flaw to overwrite existing Perl modules with malicious code. When the application subsequently invokes the modified module, the injected code executes in the context of the web application user, leading to remote code execution (RCE). The vulnerability was resolved by the vendor in version 8.05.
- Description
- An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.
- Source
- bbf0bd87-ece2-41be-b873-96928ee8fab9
- NVD status
- Modified
- Products
- lpar2rrd
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- bbf0bd87-ece2-41be-b873-96928ee8fab9
- CWE-24
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
9
🚨 PoC released for an authenticated LPAR2RRD remote code execution vulnerability; CVE-2025-54769 PoC: https://t.co/IXsSPv67FI The flaw allows an authenticated read-only user to abuse the LPAR2RRD upgrade functionality to upload a crafted file and achieve remote code executio
@DarkWebInformer
6 Oct 2026
4829 Impressions
4 Retweets
16 Likes
4 Bookmarks
1 Reply
0 Quotes
CVE-2025-54769 (CVSS:8.8, HIGH) is Awaiting Analysis. An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in..https://t.co/u7dW1Bx55M #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
3 Aug 2025
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-54769 Directory Traversal in Perl Application Enabling Authenticated Remote Code Execution https://t.co/OyPnQ82xhq
@VulmonFeeds
29 Jul 2025
78 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-54769 An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be us… https://t.co/jUwMzpvRqB
@CVEnew
28 Jul 2025
470 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:xorux:lpar2rrd:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5B49D9F5-0510-4191-B286-427ECC02C837",
"versionEndIncluding": "8.04",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]