CVE-2025-54769(xorux / lpar2rrd)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-24CWE-434CWE-648

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lpar2rrd

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Affected systems

Vendors
Products
lpar2rrd

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-06: 210-06
Referenced assets2 URLs
Full discourse2 posts
  • Dark Web Informer@DarkWebInformer

    🚨 PoC released for an authenticated LPAR2RRD remote code execution vulnerability; CVE-2025-54769 PoC: https://github.com/tunahantekeoglu/CVE-2025-54769 The flaw allows an authenticated read-only user to abuse the LPAR2RRD upgrade functionality to upload a crafted file and achieve remote code execution through directory traversal. CVSS: 8.8 Affected: LPAR2RRD ≤ 8.04 Fixed: LPAR2RRD ≥ 8.05 The PoC builds and uploads a minimal upgrade archive, then verifies successful code execution by retrieving the output of whoami.

    114057158.2K
    241.9K followersView on X
  • ThreatWire@ThreatWire_

    🚨 PoC RELEASED: CVE-2025-54769 — authenticated remote code execution in LPAR2RRD (CVSS 8.8). Root cause: a read-only authenticated user can abuse the upgrade upload path. A crafted archive whose filename includes directory traversal can still be written even when the appliance rejects the package as an invalid upgrade, overwriting Perl modules and leading to code execution as the lpar2rrd user. KoreLogic reported it as KL-001-2025-016. ⚠️ Affected: LPAR2RRD ≤ 8.04. Fixed in 8.05. CVSS 8.8 from CISA's secondary assessment. Not in CISA KEV. ⚠️ A public PoC exists; ThreatWire has not run it. 🔴 Upgrade to LPAR2RRD 8.05 or later, and review who has even read-only access to the appliance. Full breakdown 👉 https://www.threatwire.tech/news/lpar2rrd-authenticated-rce-is-cve-2025-54769 #CyberSecurity #InfoSec #RCE #LPAR2RRD

    020120540
    1.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appxoruxlpar2rrd---

Explore more