CVE-2025-27025
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/07/2025
Last modified:
03/07/2025
Description
The target device exposes a service on a specific TCP port with a configured<br />
endpoint. The access to that endpoint is granted using a Basic Authentication<br />
method. The endpoint accepts also the PUT method and it is possible to <br />
write files on the target device file system. Files are written as root.<br />
Using Postman it is possible to perform a Directory Traversal attack <br />
and write files into any location of the device file system. Similarly to the PUT method, it is possible to leverage the <br />
same mechanism to read any file from the file system by using the GET <br />
method.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH