Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2025-27590

Description

In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.

POC

Reference

No PoCs from references.

Github

- https://github.com/PuddinCat/GithubRepoSpider

- https://github.com/fatkz/CVE-2025-27590

- https://github.com/nomi-sec/PoC-in-GitHub