CVE-2025-1025 is an Arbitrary File Upload vulnerability affecting versions of the cockpit-hq/cockpit package prior to 2.4.1. Attackers can bypass upload filters by using different file extensions, potentially leading to unauthorized code execution. This vulnerability is rated High severity (CVSS 7.5) due to its low attack complexity and lack of user interaction required for exploitation, allowing an unauthenticated attacker to achieve high integrity impact. While not yet in the KEV catalog, exploit intelligence indicates the availability of Nuclei templates for this vulnerability, and it has garnered significant community discussion, suggesting active interest in its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Cockpit-Hq/Cockpit | >= 0, < 2.4.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.