Skip to content
THREATWIRE

CVE

HighPoC Available

CVE-2025-54769

LPAR2RRD authenticated file-upload path traversal to RCE

KoreLogic says Xorux LPAR2RRD through 8.04 lets an authenticated read-only user abuse the upgrade upload with directory traversal to place files arbitrarily and overwrite Perl modules for RCE. CVSS 3.1 8.8 (CISA ADP). Public PoC exists. Not in CISA KEV. Fixed in 8.05.

CVSS
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Class
RCE
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
Xorux
Products
LPAR2RRD
Affected
8.04 and prior, per KoreLogic KL-001-2025-016 and NVD CPE through 8.04 inclusive.
Fixed
8.05 and later, per the LPAR2RRD 8.05 notes on lpar2rrd.com/note800.php.
Published
29 Jul 2025
Updated
6 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2025-54769 is a file-upload directory traversal in Xorux LPAR2RRD, assigned by KoreLogic as advisory KL-001-2025-016. In versions 8.04 and prior, an authenticated read-only user can submit an upgrade package whose filename includes traversal sequences so the appliance writes the upload outside the intended upgrade location. KoreLogic states the appliance may reject the file as an invalid upgrade package and still write it to the filesystem. That write can overwrite existing Perl modules under the application install path, after which attacker-controlled logic runs when those modules are invoked through the product’s CGI scripts, producing remote code execution as the LPAR2RRD service user.

KoreLogic classifies the issue as CWE-24 (path traversal), CWE-434 (unrestricted upload of a dangerous type), and CWE-648 (incorrect use of privileged APIs). NVD published the record on 29 July 2025. CISA ADP scores CVSS 3.1 8.8 with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (High). GitHub advisory GHSA-w9qq-jmgq-wfv5 carries the same score. CISA has not listed the CVE in KEV; CISA SSVC sets exploitation to poc. Xorux documents the fix in the 8.05 notes on the LPAR2RRD announcement page.

GitHub user tunahantekeoglu (Tunahan Tekeoğlu / t4hunt) published a public C proof-of-concept repository for this CVE. The README claims an authenticated upgrade upload that verifies code execution by capturing whoami output in a web-readable proof file. ThreatWire did not run it. This record does not reprint requests, filenames, or payloads. Exploitation in the wild is not confirmed by CISA KEV.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2025-54769