CVE-2025-24350
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Apr 30, 2025
Updated: May 2, 2025
CWE ID 23
Summary
CVE-2025-24350 is a newly disclosed vulnerability affecting the "Certificates and Keys" functionality in the web application of ctrlX OS. This issue permits a remote, authenticated (low-privileged) attacker to write arbitrary certificates to arbitrary file system paths through a specially crafted HTTP request. Successful exploitation could lead to unauthorized certificate creation and potential data integrity compromises. It is essential that affected organizations apply the available patch promptly to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.