Home

Description

Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a denial of service via function handle_interface_POST_and_status.

PUBLISHED Reserved 2025-11-18 | Published 2025-12-09 | Updated 2025-12-11 | Assigner mitre

References

gh0stmezh.wordpress.com/2025/12/05/cve-2025-65573/ exploit

github.com/AllskyTeam/allsky

github.com/...allsky/blob/master/html/includes/functions.php

github.com/...ky/blob/master/html/includes/dashboard_LAN.php

github.com/...y/blob/master/html/includes/dashboard_WLAN.php

gh0stmezh.wordpress.com/2025/12/05/cve-2025-65573/

cve.org (CVE-2025-65573)

nvd.nist.gov (CVE-2025-65573)

Download JSON