CVE-2025-54769

Published Jul 29, 2025

Last updated a year ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-54769 is a directory traversal and file upload vulnerability discovered in Xorux LPAR2RRD, affecting versions up to 8.04. The issue resides in an authenticated file upload endpoint that fails to sanitize user-supplied path components, allowing the use of `../` traversal sequences. Consequently, an authenticated user with read-only privileges can bypass directory restrictions and place uploaded files into arbitrary locations on the host filesystem. Because LPAR2RRD is implemented in Perl, it dynamically loads module files from known directories at runtime. An attacker can exploit this behavior by using the directory traversal flaw to overwrite existing Perl modules with malicious code. When the application subsequently invokes the modified module, the injected code executes in the context of the web application user, leading to remote code execution (RCE). The vulnerability was resolved by the vendor in version 8.05.

Description
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.
Source
bbf0bd87-ece2-41be-b873-96928ee8fab9
NVD status
Modified
Products
lpar2rrd

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

bbf0bd87-ece2-41be-b873-96928ee8fab9
CWE-24

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

9

Configurations