CVE-2025-41359General(smallsrv / small_http_server)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing the service to execute the malicious file instead of the legitimate one. Exploiting this flaw could allow arbitrary code execution, unauthorized access to the system, or service disruption. To mitigate the risk, the service path must be properly quoted, and systems must be kept up to date with security patches, while restricting physical and network access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-428

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • small_http_server

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
small_http_server

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Technical Details · 2026-03-29: 103-2603-29
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-261
General1
2026-03-291
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-41359 Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\htt… https://www.cve.org/CVERecord?id=CVE-2025-41359

    Post summary

    The text announces CVE-2025-41359 as an unquoted service path issue in Small HTTP Server 3.06.36, providing technical details but no exploit, patch, or PoC information.

    00010195
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-41359 - Multiple vulnerabilities in Small HTTP server by Smallsrv Intel Report: https://ift.tt/HeO3u5o

    Post summary

    The alert announces CVE-2025-41359 affecting the Small HTTP server, links to an intel report, but offers no technical, exploitation, or mitigation details.

    00000187
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsmallsrvsmall_http_server---

Explore more