Improper Neutralisation in Revive Adserver by Revive Adserver
CVE-2025-52666

2.7LOW

Key Information:

Vendor

Revive

Vendor
CVE Published:
20 November 2025

What is CVE-2025-52666?

A vulnerability exists in Revive Adserver versions 5.5.2 and 6.0.1, and earlier, where improper handling of format characters in the settings can lead to a PHP fatal error. This issue can disrupt the admin user console functionality, impacting the ability of administrators to manage the system effectively. Properly mitigating this vulnerability is essential to ensure uninterrupted admin access.

Affected Version(s)

Revive Adserver 6.0.1

Revive Adserver 5.5.2

Revive Adserver 6.0.2

References

CVSS V3.0

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52666 : Improper Neutralisation in Revive Adserver by Revive Adserver