Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
References
| Link | Resource |
|---|---|
| https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts | Exploit Third Party Advisory |
| https://www.xspeeder.com | Product |
| https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts | Exploit Third Party Advisory |
Configurations
History
09 Jan 2026, 20:33
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Xspeeder
Xspeeder sxzos |
|
| CWE | CWE-94 | |
| CPE | cpe:2.3:o:xspeeder:sxzos:*:*:*:*:*:*:*:* | |
| References | () https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts - Exploit, Third Party Advisory | |
| References | () https://www.xspeeder.com - Product |
29 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://pwn.ai/blog/cve-2025-54322-zeroday-unauthenticated-root-rce-affecting-70-000-hosts - |
27 Dec 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-27 14:15
Updated : 2026-01-09 20:33
NVD link : CVE-2025-54322
Mitre link : CVE-2025-54322
CVE.ORG link : CVE-2025-54322
JSON object : View
Products Affected
xspeeder
- sxzos
