PT-2025-50080 · Unknown · Snmp Web Pro

CVE-2025-65287

·

Published

2025-12-09

·

Updated

2025-12-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SNMP Web Pro version 1.1
Description An unauthenticated directory traversal issue exists in the cgi-bin/upload.cgi component. The component concatenates user-supplied parameters directly onto a base path (/var/www/files/userScript/) using memcpy and strcat without proper validation or sanitization. This allows attackers to use "../" sequences to access files outside the intended directory. Additionally, the download functionality echoes unsanitized parameters into the Content-Disposition header, potentially leading to header injection.
Recommendations Apply updates to address the issue in SNMP Web Pro version 1.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65287

Affected Products

Snmp Web Pro