Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-15545

Опубликовано: 29 янв. 2026
Источник: nvd
EPSS Низкий

Описание

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.

EPSS

Процентиль: 6%
0.00024
Низкий

Дефекты

CWE-20

Связанные уязвимости

github
9 дней назад

The backup restore function does not properly validate unexpected or unrecognized tags within the backup file. When such a crafted file is restored, the injected tag is interpreted by a shell, allowing execution of arbitrary commands with root privileges. Successful exploitation allows the attacker to gain root-level command execution, compromising confidentiality, integrity and availability.

EPSS

Процентиль: 6%
0.00024
Низкий

Дефекты

CWE-20