
🚨 PoC released for an authenticated LPAR2RRD remote code execution vulnerability; CVE-2025-54769 PoC: https://github.com/tunahantekeoglu/CVE-2025-54769 The flaw allows an authenticated read-only user to abuse the LPAR2RRD upgrade functionality to upload a crafted file and achieve remote code execution through directory traversal. CVSS: 8.8 Affected: LPAR2RRD ≤ 8.04 Fixed: LPAR2RRD ≥ 8.05 The PoC builds and uploads a minimal upgrade archive, then verifies successful code execution by retrieving the output of whoami.

