CVE-2025-53880

A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses.
CVSS

No CVSS.

Configurations

No configuration.

History

30 Oct 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-30 11:15

Updated : 2025-10-30 15:03


NVD link : CVE-2025-53880

Mitre link : CVE-2025-53880

CVE.ORG link : CVE-2025-53880


JSON object : View

Products Affected

No product.

CWE
CWE-35

Path Traversal: '.../...//'