CVE-2025-54792 is a critical Man-in-the-Middle (MitM) vulnerability affecting LocalSend versions 1.16.1 and below, an open-source file sharing application. An unauthenticated attacker on the same local network can exploit this flaw to impersonate legitimate devices, silently intercepting, reading, and modifying file transfers. This vulnerability carries a CVSS score of 6.8 (Medium) due to its adjacent attack vector, high impact on confidentiality and integrity, and low attack complexity. While there is no known active exploitation, public exploit code, or significant community discussion, the ease of implementation and severe potential for data theft or malware injection pose an immediate security risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.0CPE matchmatch criteria | cpe:2.3:a:localsend:localsend:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.