Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5558 | In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web. |
Github GHSA |
GHSA-jx6p-9c26-g373 | Oxidized Web RANCID migration page allows unauthenticated user to gain control over Linux user account |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 04 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user account that is running oxidized-web. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-04T18:51:34.394Z
Reserved: 2025-03-03T00:00:00.000Z
Link: CVE-2025-27590
Updated: 2025-03-04T18:51:31.033Z
Status : Received
Published: 2025-03-03T04:15:09.020
Modified: 2025-03-03T04:15:09.020
Link: CVE-2025-27590
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:10Z
EUVD
Github GHSA