Configuration Modification Vulnerability in ELOG by Ritt
CVE-2025-64348

9.3CRITICAL

Key Information:

Vendor

Elog

Status
Vendor
CVE Published:
31 October 2025

What is CVE-2025-64348?

An authentication issue in ELOG permits users to alter or overwrite its configuration file, potentially leading to denial of service scenarios. If the system is executed with the '-x' command line option, malicious actors could exploit this flaw to run operating system commands on the host machine, despite ELOG’s default settings which do not enable such actions. It's crucial to evaluate the security configurations of affected ELOG versions to mitigate potential risks.

Affected Version(s)

ELOG *

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karl Meister, CISA
.
CVE-2025-64348 : Configuration Modification Vulnerability in ELOG by Ritt