CVE-2019-25709Disclosure(codefuture / image_hosting_script)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch codefuture image_hosting_script systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • image_hosting_script

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
image_hosting_script

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-12: 2Mentions · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-12: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-12: 2Technical Details · 2026-04-13: 104-1204-13
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-122
Disclosure2
2026-04-131
Disclosure1
Full discourse3 posts
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: Totolink CGI Handler Risks (CVSS 9.8-9.8) Affected: Totolink A7100RU; CF Image Hosting Script Internet-facing exposure dominates as remote CGI vulnerabilities enable command execution and data exposure. • CVE-2026-6112 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setRadvdCfg allows manipulation of maxRtrAdvInterval to enable OS command injection; remote exploitation possible. • CVE-2026-6113 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setTtyServiceCfg enables manipulation of ttyEnable causing OS command injection; remote exploitation possible. • CVE-2026-6114 (CVSS 9.8) Totolink A7100RU 7.4cu.2313_b20191024; CGI Handler setNetworkCfg manipulation of proto leads to OS command injection; remote exploitation possible. • CVE-2019-25709 (CVSS 9.8) CF Image Hosting Script 1.6.5; Unauthenticated attackers can download and decode the application database by accessing imgdb.db in upload/data, exposing delete IDs that enable mass deletion of pictures. Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (process spawning, webshell/file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces several critical CVEs affecting Totolink routers and a CF Image Hosting script, detailing command injection vulnerabilities and urging immediate patching and mitigation.

    0000042
    98 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2019-25709: CRITICAL] CF Image Hosting Script 1.6.5 vulnerability enables unauthenticated attackers to access database files, extract sensitive data, and delete pictures stored on the application.#cve,CVE-2019-25709,#cybersecurity https://cvefind.com/CVE-2019-25709

    Post summary

    The post announces CVE‑2019‑25709 in CF Image Hosting Script 1.6.5, detailing unauthenticated database file access and data extraction. No PoC, exploit, active usage, patch, or debunking is mentioned.

    0000041
    620 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2019-25709: CF Image H... Plaintext delete IDs in an exposed SQLite database = instant mass image wipeout via URL parameter manipulation. #WebAppSec #DatabaseExposure. https://zerodaysignal.com/vulnerability/CVE-2019-25709 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2019‑25709, describing how plaintext delete IDs in an exposed SQLite database allow mass image deletion via URL manipulation, and links to a vulnerability page for more details.

    0000057
    217 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodefutureimage_hosting_script1.6.5--

Explore more