Directory Traversal Vulnerability in Service with Basic Authentication on Target Device
CVE-2025-27025
What is CVE-2025-27025?
The target device is vulnerable due to a misconfigured service that exposes a TCP endpoint secured only by Basic Authentication. The vulnerability arises from the ability to use the PUT method to write files directly to the device's file system, with the potential to write in any directory, including system-level directories, given root-level permissions. Furthermore, attackers can employ the GET method in tandem with a Directory Traversal technique to read sensitive files located anywhere on the device. Utilizing tools like Postman, an attacker can easily exploit this vulnerability, compromising the integrity and confidentiality of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
G42 6.1.3 < 7.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
