Vulnerabilities
2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-27590 | Unauthenticated Path Traversal in Oxidized Web RANCID Migration Page CVE-2025-27590 is a path traversal flaw (CWE-22) in the RANCID migration page of oxidized-web, the web interface for the Oxidized network device configuration backup tool, affecting all versions before 0.15.0. An unauthenticated attacker can send a crafted HTTP request to the migration page with attacker-controlled path input, allowing them to manipulate files on the host as the service. As a result, the attacker gains control over the Linux user account under which oxidized-web runs, which typically means the ability to read, write, or execute as that account on the Oxidized server — a system that stores network device credentials and configurations. Any deployment running oxidized-web prior to 0.15.0 is affected, including installations where the web interface is exposed to untrusted networks. Exploitation has not been observed in the wild and no public proof-of-concept is known, but the 27.6% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within 30 days. Do: Upgrade oxidized-web to version 0.15.0 or later. Until then, restrict access to the oxidized-web interface to trusted management networks via firewall rules, ACLs, or an authenticating reverse proxy, since the vulnerable page requires no authentication. Also audit the Linux account running oxidized-web (e.g., check authorized_keys, cron jobs, and recent activity) for signs of compromise. | 9.8 | 28% |
| nichelikely low thousands of deployments worldwide, mostly on internal management networks; internet-exposed instances probably in the hundreds | ||
| CVE-2019-25088 | A vulnerability was found in ytti Oxidized Web. A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 5.4 | <1% |
| — |