CVE-2025-53880
A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-35
- Published
- 2025-10-30
- Last modified
- 2026-03-13
Affected products
- SUSE Container suse/manager/4.3/proxy-httpd:latest
- SUSE Container suse/manager/5.0/x86_64/proxy-httpd:latest
- SUSE Container suse/multi-linux-manager/5.1/x86_64/proxy-httpd:latest
- SUSE SUSE Manager Proxy LTS 4.3
Weakness type
Related vulnerabilities
- CVE-2026-20513 — In Audio HAL, there is a possible information disclosure due to improper input validation. This...
- CVE-2026-56089 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low...
- CVE-2026-59909 — Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low...
- CVE-2026-28157 — WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability
- CVE-2026-69109 — A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The...
- CVE-2026-13716 — Path Traversal: '.../...//' in Crafty Controller
- CVE-2026-59115 — Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
- CVE-2026-66695 — WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability