KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 3.0%
from disclosure to weapon2 days
Published on NVDJul 28
1st PoC+2d
exploitation probability
3.0%top 14% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Xorux · LPAR2RRDpublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/52391unverifiedgithubgithub.com/byteReaper77/CVE-2025-54769★ 2⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.