# CVE-2025-54769

## Summary

- **CVE ID:** CVE-2025-54769
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-24, CWE-434, CWE-648
- **Published:** Jul 28, 2025
- **Last Modified:** Mar 12, 2026

## Description

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing.  This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an attacker.

## Affected Products

- Xorux — LPAR2RRD (8.04)

## References

- [CNA](https://korelogic.com/Resources/Advisories/KL-001-2025-016.txt)
- [CNA](https://lpar2rrd.com/note800.php)
- [CVE](http://seclists.org/fulldisclosure/2025/Jul/19)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 3.11%
- **EPSS Percentile:** 87.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._