Home

Description

A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses.

PUBLISHED Reserved 2025-07-11 | Published 2025-10-30 | Updated 2025-10-30 | Assigner suse




HIGH: 8.7CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-35: Path Traversal

Product status

Default status
unaffected

? (custom) before 4.3.11-150400.3.15.3
affected

Default status
unaffected

? (custom) before 5.0.3-150600.3.6.4
affected

Default status
unaffected

? (custom) before 5.1.3-150700.3.3.3
affected

Default status
unaffected

? (custom) before 4.3.11-150400.3.15.3
affected

Credits

Paolo Perego of SUSE finder

References

bugzilla.suse.com/show_bug.cgi?id=CVE-2025-53880

cve.org (CVE-2025-53880)

nvd.nist.gov (CVE-2025-53880)

Download JSON