Path Traversal Vulnerability in tftpsync by SUSE
CVE-2025-53880
Key Information:
- Vendor
Suse
- Status
- Vendor
- CVE Published:
- 30 October 2025
What is CVE-2025-53880?
A Path Traversal vulnerability exists in the tftpsync application, allowing an adjacent network remote attacker to manipulate files on the filesystem. This can include writing or deleting files using the privileges of the unprivileged wwwrun user. While the endpoint does not require authentication, access is controlled to a specified list of allowed IP addresses, which could still pose significant risk if those addresses are compromised.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Container suse/manager/4.3/proxy-httpd:latest ? < 4.3.11-150400.3.15.3
Container suse/manager/5.0/x86_64/proxy-httpd:latest ? < 5.0.3-150600.3.6.4
Container suse/multi-linux-manager/5.1/x86_64/proxy-httpd:latest ? < 5.1.3-150700.3.3.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved