CVE-2025-30914

CVSS 3.1 Score 4.4 of 10 (medium)

Details

Published Mar 27, 2025
CWE ID 918

Summary

CVE-2025-30914 is a Server-Side Request Forgery (SSRF) vulnerability affecting XpeedStudio Metform, from an unknown version up to 3.9.2. An attacker can exploit this issue by crafting malicious HTTP requests to manipulate Metform's backend functionalities. The vulnerability allows the attacker to gain unauthorized access to internal resources or perform unauthorized actions on the affected server, potentially leading to data theft or server compromise. This security flaw poses a significant risk to organizations using the XpeedStudio Metform software and requires immediate attention and patching to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share