← back
CVE-2025-34300criticalobserved exploitationCWE-1336CWE-20

Sawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE

97Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 10epss 51%
from disclosure to weapon47 days
Published on NVDJul 16
1st PoC+47d
metasploitJul 16
VulnCheck+22d
exploitation probability
51%top 1% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
In short

Sawtooth Software Lighthouse Studio has a flaw that lets anyone on the internet run any command they want on the server, without needing a password. This is extremely dangerous because attackers can take over the entire system.

Technical detail

A template injection vulnerability in the ciwweb.pl Perl application allows unauthenticated remote code execution. The attack vector is HTTP requests to the web interface; no authentication or special conditions are required. Successful exploitation results in arbitrary command execution with server privileges.

Summary generated and translated by AI from the official description.
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the  ciwweb.pl http://ciwweb.pl/  Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.