# CVE-2025-54768

## Summary

- **CVE ID:** CVE-2025-54768
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-648
- **Published:** Jul 28, 2025
- **Last Modified:** Mar 12, 2026

## Description

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application users. The endpoint can be used to download logs from the appliance configuration, exposing sensitive information.

## Affected Products

- Xorux — LPAR2RRD (8.04)

## References

- [CNA](https://korelogic.com/Resources/Advisories/KL-001-2025-015.txt)
- [CNA](https://lpar2rrd.com/note800.php)
- [CVE](http://seclists.org/fulldisclosure/2025/Jul/18)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 4.38%
- **EPSS Percentile:** 90.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._