FOG's authentication bypass leads to full SQL DB dump
90Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 9.9epss 19%
from disclosure to weapon0 days
Published on NVDSep 6
1st PoCSep 6
VulnCheck+93d
exploitation probability
19%top 3% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass vulnerability. It is possible for an attacker to perform an unauthenticated DB dump where they could pull a full SQL DB without credentials. A fix is expected to be released 9/15/2025. To address this vulnerability immediately, upgrade to the latest version of either the dev-branch or working-1.6 branch. This will patch the issue for users concerned about immediate exposure. See the FOG Project documentation for step-by-step upgrade instructions: https://docs.fogproject.org/en/latest/install-fog-server#choosing-a-fog-version.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Affected products
FOGProject · fogprojectpublic PoCs found — 2
githubgithub.com/casp3r0x0/CVE-2025-58443★ 2vulncheckvulncheck.com/xdb/85070250aeffunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.