PT-2025-21368 · Atheros · Atheos

·

CVE-2025-47788

·

Published

2025-05-15

·

Updated

2025-05-15

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: Atheos versions prior to v602
Description: Atheos is a self-hosted browser-based cloud IDE. The $target parameter in "/controller.php" was not properly validated, which could allow an attacker to execute arbitrary files on the server via path traversal.
Recommendations: For versions prior to v602, update to v602 to resolve the issue. As a temporary workaround, consider restricting access to the "/controller.php" endpoint to minimize the risk of exploitation. Avoid using the $target parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09359
CVE-2025-47788
GHSA-X9VW-6VFX-7RX5

Affected Products

Atheos