CVE-2025-29331

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
26/06/2025
Last modified:
10/07/2025

Description

An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mhsanaei:3x-ui:*:*:*:*:*:*:*:* 2.5.3 (excluding)