Insecure Authentication in File Browser Allows Brute-Force Attacks
CVE-2025-52997

5.9MEDIUM

Key Information:

Vendor
CVE Published:
30 June 2025

What is CVE-2025-52997?

File Browser, a file management tool, has a vulnerability that arises from a lack of a robust password policy and inadequate brute-force attack protection. This weakness allows attackers to potentially perform brute-force attacks, thereby compromising user accounts by retrieving passwords across an instance. The issue has been resolved in version 2.34.1 where enhanced authentication security measures have been implemented.

Affected Version(s)

filebrowser < 2.34.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52997 : Insecure Authentication in File Browser Allows Brute-Force Attacks