CVE-2025-54769
LPAR2RRD authenticated file-upload path traversal to RCE
KoreLogic says Xorux LPAR2RRD through 8.04 lets an authenticated read-only user abuse the upgrade upload with directory traversal to place files arbitrarily and overwrite Perl modules for RCE. CVSS 3.1 8.8 (CISA ADP). Public PoC exists. Not in CISA KEV. Fixed in 8.05.
- CVSS
- 8.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Class
- RCE
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Xorux
- Products
- LPAR2RRD
- Affected
- 8.04 and prior, per KoreLogic KL-001-2025-016 and NVD CPE through 8.04 inclusive.
- Fixed
- 8.05 and later, per the LPAR2RRD 8.05 notes on lpar2rrd.com/note800.php.
- Published
- 29 Jul 2025
- Updated
- 6 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2025-54769 is a file-upload directory traversal in Xorux LPAR2RRD, assigned by KoreLogic as advisory KL-001-2025-016. In versions 8.04 and prior, an authenticated read-only user can submit an upgrade package whose filename includes traversal sequences so the appliance writes the upload outside the intended upgrade location. KoreLogic states the appliance may reject the file as an invalid upgrade package and still write it to the filesystem. That write can overwrite existing Perl modules under the application install path, after which attacker-controlled logic runs when those modules are invoked through the product’s CGI scripts, producing remote code execution as the LPAR2RRD service user.
KoreLogic classifies the issue as CWE-24 (path traversal), CWE-434 (unrestricted upload of a dangerous type), and CWE-648 (incorrect use of privileged APIs). NVD published the record on 29 July 2025. CISA ADP scores CVSS 3.1 8.8 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (High). GitHub advisory GHSA-w9qq-jmgq-wfv5 carries the same score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to poc. Xorux documents the fix in the 8.05 notes on the LPAR2RRD announcement page.
GitHub user tunahantekeoglu (Tunahan Tekeoğlu / t4hunt) published a public C proof-of-concept repository for this CVE. The README claims an authenticated upgrade upload that verifies code execution by capturing whoami output in a web-readable proof file. ThreatWire did not run it. This record does not reprint requests, filenames, or payloads. Exploitation in the wild is not confirmed by CISA KEV.