CVE-2025-10327PoC(sourcefabric / rpi-jukebox-rfid)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for sourcefabric rpi-jukebox-rfid systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/api/playlist/shuffle.php. Executing manipulation of the argument playlist can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • rpi-jukebox-rfid

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
rpi-jukebox-rfid

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-24: 1PoC Mentioned / Linked · 2026-08-24: 1Exploit Tool / Code · 2026-08-24: 1Technical Details · 2026-08-24: 108-24
Signal classification1 categories
PoC
1100.0%
Full discourse1 post
  • MrKay@mr_kay7
    PoC

    Day52 #200Dayschallenge CVE & NVD identify bugs, but ExploitDB shows the attacks! I looked up a real Remote Command Execution exploit CVE-2025-10327 to see the Python Proof of Concept (PoC) code. Seeing how vulnerabilities are actually weaponized is wild! #Cybersecurity #CVE https://t.co/CAD3qxPtt7

    Post summary

    The tweet reports that the author reviewed the Python PoC for CVE-2025-10327, a remote command execution exploit, highlighting its weaponization potential.

    1112621.5K
    972 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsourcefabricrpi-jukebox-rfid---

Explore more