Critical severity9.3NVD Advisory· Published May 7, 2025· Updated Jun 17, 2026
CVE-2025-2777
CVE-2025-2777
Description
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 0
Patches
Vulnerability mechanics
References
2- labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/nvdExploitThird Party Advisory
- documentation.sysaid.com/docs/24-40-60nvdRelease Notes
News mentions
0No linked articles in our index yet.