VYPR
Critical severity10.0OSV Advisory· Published Dec 16, 2025· Updated Jun 17, 2026

CVE-2025-63414

CVE-2025-63414

Description

A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP request to the /html/execute.php endpoint with a malicious payload in the id parameter, an attacker can execute arbitrary commands on the underlying operating system, leading to full remote code execution (RCE).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • AllskyTeam/AllskyOSV3 versions
    V0.2, V0.4, v0.5, …+ 2 more
    • (no CPE)range: V0.2, V0.4, v0.5, …
    • (no CPE)range: v2024.12.06_06
    • cpe:2.3:a:allskyteam:allsky:2024.12.06_06:*:*:*:*:*:*:*
  • Range: v2024.12.06_06

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.