CVE-2025-1086

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 7, 2025
CWE ID 23
CWE ID 24

Summary

CVE-2025-1086 is a critical vulnerability affecting the Safetytest Cloud-Master Server up to version 1.1.1. The issue lies within unknown code in the /static/ directory and allows for a remote attacker to initiate path traversal with the manipulation of '../filedir'. The exploit for this vulnerability has been disclosed to the public, increasing the risk of potential attacks. Despite early notification, the vendor has yet to respond to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share