CVE-2025-40549

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled.
Configurations

No configuration.

History

18 Nov 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-18 09:15

Updated : 2025-11-18 14:06


NVD link : CVE-2025-40549

Mitre link : CVE-2025-40549

CVE.ORG link : CVE-2025-40549


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')