CVE-2025-29331 describes a critical arbitrary code execution vulnerability affecting MHSanaei 3x-ui versions prior to 2.5.3. This flaw, rated 9.8 CVSS, stems from the software passing an unchecked certificate option to wget during updates, allowing remote attackers to execute malicious code without authentication. While no active exploitation, public exploit code, or significant community discussion has been observed, its high severity and straightforward exploitability warrant immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.3CPE matchmatch criteria | cpe:2.3:a:mhsanaei:3x-ui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.