CVE-2025-59793Disclosure(rocketsoftware / trufusion_enterprise)

LOWCVSS 9.4 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for rocketsoftware trufusion_enterprise systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to be included. This allows writing files to arbitrary local filesystem locations and may subsequently lead to remote code execution.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-35

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trufusion_enterprise

Threat summary

  • Public PoC and exploit tooling are both present
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-17); latest day: 2
  • 6 total mentions across 2 days

Affected systems

Products
trufusion_enterprise

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-02-17: 4Mentions · 2026-03-23: 2PoC Mentioned / Linked · 2026-02-17: 1Exploit Tool / Code · 2026-02-17: 1Technical Details · 2026-02-17: 4Technical Details · 2026-03-23: 202-1703-23
Signal classification3 categories
Disclosure
350.0%
General
233.3%
Exploit
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-174
Disclosure1Exploit1General2
2026-03-232
Disclosure2
Full discourse6 posts
  • Julien | MrTuxracer 🇪🇺@MrTuxracer
    General

    Pwning TRUfusion Enterprise again: chaining a pre-auth SSRF (CVE-2025-32355), a default password, and a path traversal (CVE-2025-59793) to gain RCE. #security https://www.rcesecurity.com/2026/02/when-audits-fail-from-pre-auth-ssrf-to-rce-in-trufusion-enterprise/

    Post summary

    The post outlines how chaining two CVEs (CVE‑2025‑32355 and CVE‑2025‑59793) in TRUfusion Enterprise can lead to remote code execution, but it provides no PoC, exploit code, patch, or evidence of active exploitation.

    212068345.1K
    38.4K followersView on X
  • RCE Security@rcesecurity
    General

    Pwning TRUfusion Enterprise again: chaining a pre-auth SSRF (CVE-2025-32355), a default password, and a path traversal (CVE-2025-59793) to gain RCE. #security https://www.rcesecurity.com/2026/02/when-audits-fail-from-pre-auth-ssrf-to-rce-in-trufusion-enterprise/

    Post summary

    The post describes chaining pre‑auth SSRF, default password, and path traversal vulnerabilities to achieve RCE, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    011039192.7K
    237 followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #AppSec 1⃣. CVE-2026-25506: Pwning Supercomputers - A 20yo vulnerability in Munge https://blog.lexfo.fr/munge-heap-buffer-overflow.html // Exploitation involved heap spraying, tcache poisoning, and crafting fake chunks to leak internal addresses and ultimately retrieve the Munge secret key 2⃣. ClickOnce + AppDomainManager Injection + ProxyBlob SOCKS5 -> Initial Access https://github.com/dazzyddos/ClickOnceBlobber // It automates the process of patching, compiling, and manifest updating, allowing attackers to embed malicious DLLs into legitimate, signed ClickOnce apps without breaking their signatures or raising suspicion 3⃣. CVE-2025-59793: From Pre-Auth SSRF to RCE in TRUfusion Enterprise https://www.rcesecurity.com/2026/02/when-audits-fail-from-pre-auth-ssrf-to-rce-in-trufusion-enterprise // Exploit chains the path traversal with the previously described SSRF (CVE-2025-32355)

    Post summary

    The text presents detailed exploitation techniques and a functional tool for CVE‑2026‑25506 and CVE‑2025‑59793, but does not report active in‑the‑wild use or patches.

    10031396
    3.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-59793 Path Traversal in Rocket TRUfusion Enterprise Enabling Arbitrary File Write https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-59793

    Post summary

    A Path Traversal vulnerability in Rocket TRUfusion Enterprise that allows arbitrary file writes is disclosed, with no PoC, exploit, patch, or active exploitation details.

    0001039
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-59793 Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However,… https://www.cve.org/CVERecord?id=CVE-2025-59793 ----- Traducción: CVE-2025-59793 Roc… http://infoflow.cloud`

    Post summary

    The text announces CVE-2025-59793, revealing that authenticated users can upload files via a specific endpoint in Rocket TRUfusion Enterprise, but it offers no PoC, exploit code, or patch information.

    0000046
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-59793 Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However,… https://www.cve.org/CVERecord?id=CVE-2025-59793

    Post summary

    The snippet announces that Rocket TRUfusion Enterprise (v7.10.5 and earlier) allows authenticated users to upload files via a specific endpoint, highlighting the vulnerability without providing a PoC, patch, or evidence of active exploitation.

    00000267
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Approcketsoftwaretrufusion_enterprise---

Explore more