CVE-2025-24968

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 4, 2025
CWE ID 284

Summary

CVE-2025-24968 is a vulnerability affecting the reNgine automated reconnaissance framework for web applications. Attackers with certain roles, such as `penetration_tester` or `auditor`, can exploit an unrestricted project deletion flaw to erase all projects and take over the entire system. This can result in the attacker gaining control over user accounts, including Sys Admins, and configuring critical settings like API keys and user preferences. The vulnerability affects all reNgine versions up to and including 2.20, and there are currently no known workarounds. Users are urged to keep an eye out for future software releases that address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share