ZeroHour

CVE-2025-27590

niche

Unauthenticated Path Traversal in Oxidized Web RANCID Migration Page

CVSS 3.1
9.8 critical
EPSS
28%p98
Published
()
Modified
AI analysis

CVE-2025-27590 is a path traversal flaw (CWE-22) in the RANCID migration page of oxidized-web, the web interface for the Oxidized network device configuration backup tool, affecting all versions before 0.15.0. An unauthenticated attacker can send a crafted HTTP request to the migration page with attacker-controlled path input, allowing them to manipulate files on the host as the service. As a result, the attacker gains control over the Linux user account under which oxidized-web runs, which typically means the ability to read, write, or execute as that account on the Oxidized server — a system that stores network device credentials and configurations. Any deployment running oxidized-web prior to 0.15.0 is affected, including installations where the web interface is exposed to untrusted networks. Exploitation has not been observed in the wild and no public proof-of-concept is known, but the 27.6% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within 30 days.

What to do: Upgrade oxidized-web to version 0.15.0 or later. Until then, restrict access to the oxidized-web interface to trusted management networks via firewall rules, ACLs, or an authenticating reverse proxy, since the vulnerable page requires no authentication. Also audit the Linux account running oxidized-web (e.g., check authorized_keys, cron jobs, and recent activity) for signs of compromise.

Affected
oxidized web project oxidized weball versions before 0.15.0
Estimated exposure
nichelikely low thousands of deployments worldwide, mostly on internal management networks; internet-exposed instances probably in the hundreds — Oxidized is a niche open-source RANCID successor used mainly by network operations teams and typically deployed on internal management networks with no public install-count telemetry, so the estimate relies on community adoption patterns…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web.

Vendors
oxidized web project
Products
oxidized web
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.