CVE-2025-54336 is a critical authentication bypass vulnerability in Plesk Obsidian 18.0.70, stemming from an insecure password comparison function (_isAdminPasswordValid) that uses "==" instead of a strict comparison. This flaw allows an unauthenticated attacker to log in as an administrator if the legitimate password starts with "0e" followed by any digit string, by providing a different string that evaluates to 0.0 (e.g., "0e0"). With a CVSS score of 9.8 (CRITICAL), successful exploitation grants full confidentiality, integrity, and availability compromise. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.