CVE-2025-49415 is a Path Traversal vulnerability (CWE-22) affecting Fastw3b LLC FW Gallery versions up to and including 8.0.0. This flaw allows an attacker to access restricted directories, rated with a high CVSS score of 8.6, indicating a network-based attack with low complexity that can lead to high impact on availability. While there is no known active exploitation (KEV) or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including a mention in a Project Zero article. Its EPSS score is low, suggesting a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Fastw3b LLC | FW Gallery | >= 0, <= 8.0.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.