CVE-2025-27920
KEVnicheDirectory Traversal in Srimax Output Messenger Before 2.0.63
CISA: Srimax Output Messenger Directory Traversal Vulnerability
Output Messenger versions before 2.0.63 contain a directory traversal flaw (CWE-24) caused by improper handling of file paths in application parameters. An attacker who submits ../ sequences in these parameters can reach files outside the intended directory, potentially retrieving configuration files or other sensitive files from the server. The CVSS vector indicates network access with low privileges is required, so a low-privileged user account is sufficient to trigger the flaw. Any organization running Output Messenger below 2.0.63 is affected, and the flaw has been actively exploited: a Türkiye-aligned APT group reportedly used it as a zero-day against Kurdish military servers in Iraq, deploying Golang backdoors, an activity also observed by Microsoft. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2025-05-19, requiring federal agencies to apply vendor mitigations, follow BOD 22-01 guidance, or discontinue use of the product.
What to do: Upgrade Srimax Output Messenger to version 2.0.63 or later per the vendor's instructions, as required by CISA's KEV entry (or follow BOD 22-01 guidance for federal cloud services). Organizations that cannot patch promptly should restrict network access to Output Messenger Server and review affected hosts for signs of compromise, including unexpected Golang backdoor binaries or processes and unauthorized access to or modification of configuration files.
| Srimax Output Messenger | all versions before 2.0.63 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
- Affected
- Srimax Output Messenger
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- srimax
- Products
- output messenger
- Weakness
- CWE-24
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H