CVE-2025-63414

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP request to the /html/execute.php endpoint with a malicious payload in the id parameter, an attacker can execute arbitrary commands on the underlying operating system, leading to full remote code execution (RCE).
Configurations

Configuration 1 (hide)

cpe:2.3:a:allskyteam:allsky:2024.12.06_06:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-16 17:16

Updated : 2025-12-31 00:25


NVD link : CVE-2025-63414

Mitre link : CVE-2025-63414

CVE.ORG link : CVE-2025-63414


JSON object : View

Products Affected

allskyteam

  • allsky
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')