LPAR2RRD authenticated RCE is CVE-2025-54769
KoreLogic disclosed CVE-2025-54769 in Xorux LPAR2RRD through 8.04: an authenticated read-only user can abuse the upgrade upload with directory traversal to overwrite Perl modules and run code. CVSS 8.8. Public PoC exists. Fixed in 8.05. Not in CISA KEV.
Published 6 Oct 2026
What happened
On 28 July 2025 KoreLogic published advisory KL-001-2025-016 for Xorux LPAR2RRD, tracked as CVE-2025-54769. The CNA title is a file-upload directory traversal. An authenticated read-only user can place an uploaded upgrade file at a chosen filesystem path, overwrite application Perl modules, and achieve remote code execution. NVD published the CVE on 29 July 2025. Xorux lists the issue in the 8.05 notes on the LPAR2RRD announcement page.
Who is affected
Operators running LPAR2RRD 8.04 or earlier are in scope, including deployments KoreLogic tested on a Xormon Original appliance. Exploitation requires a valid authenticated session with at least read-only privileges and access to the upgrade upload feature. Installations already on 8.05 or later, per the vendor notes, are outside the fixed range described here. Unauthenticated outsiders without credentials are not the attacker model for this CVE.
What is confirmed
KoreLogic’s advisory states that altering the upgrade upload filename with directory traversal causes the appliance to write the file where the attacker chooses. The product may respond that the file does not look like a valid upgrade package while still writing it. Overwriting Perl modules under the application bin path lets attacker-controlled logic run when those modules are later invoked through the product’s CGI entry points, as the LPAR2RRD service user. KoreLogic credits Jim Becher and lists CWE-24, CWE-434, and CWE-648. Disclosure timeline shows vendor remediation ahead of public release, with 8.05 published around 25 July 2025.
CISA ADP scores CVSS 3.1 8.8 (High) with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. GHSA-w9qq-jmgq-wfv5 mirrors that score. CISA has not listed CVE-2025-54769 in KEV. CISA SSVC sets exploitation to poc.
GitHub user tunahantekeoglu (Tunahan Tekeoğlu, publishing as t4hunt) released a public C repository for CVE-2025-54769. The README describes an authenticated upgrade-path PoC that claims to verify execution by writing and retrieving a proof file whose contents are whoami output. ThreatWire did not run the project. Availability is therefore PoC.
What is not confirmed
Exploitation in the wild is not confirmed by CISA KEV. ThreatWire did not reproduce the KoreLogic steps or the third-party PoC against a live appliance. The public PoC repository is recent (created October 2026), has no stars, and is a single C source file plus README and MIT license; that packaging is consistent with a narrow demo, not evidence of mass exploitation. Claims of reverse shells or persistence go beyond what that README states for itself.
What to do
Upgrade LPAR2RRD to 8.05 or later from Xorux. Until then, restrict who can authenticate to the management UI, remove unnecessary read-only accounts, and treat unexpected files under the application install path as hostile. After upgrading, rotate credentials for accounts that had access during the exposure window and review the appliance for unauthorized Perl or CGI changes.
Sources: KoreLogic KL-001-2025-016, LPAR2RRD note800.php, NVD and CVE.org for CVE-2025-54769, and GHSA-w9qq-jmgq-wfv5.