Path Traversal Vulnerability in WaveView Client Affecting WaveStore Server
CVE-2025-65076

8.6HIGH

Key Information:

Vendor

Wavestore

Vendor
CVE Published:
16 December 2025

What is CVE-2025-65076?

The WaveView client is prone to a path traversal vulnerability that allows high-privileged attackers to execute a restricted set of commands on the associated WaveStore Server. This flaw can be exploited to read or delete files on the server due to improper handling of script commands executed with root privileges. The vulnerability is particularly critical as it enables attackers to maneuver within the filesystem of the server, potentially leading to significant data loss or compromise. This issue was addressed in version 6.44.44, underscoring the importance of maintaining updated software to mitigate security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WaveStore Server 0 < 6.44.44

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julia Zduńczyk
.