High severity8.8OSV Advisory· Published Dec 9, 2025· Updated Jun 17, 2026
CVE-2025-65573
CVE-2025-65573
Description
Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a denial of service via function handle_interface_POST_and_status.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3V0.2, V0.4, v0.5, …+ 2 more
- (no CPE)range: V0.2, V0.4, v0.5, …
- cpe:2.3:a:allskyteam:allsky:2024.12.06_06:*:*:*:*:*:*:*
- (no CPE)range: = 2024.12.06_06
Patches
Vulnerability mechanics
References
4- gh0stmezh.wordpress.com/2025/12/05/cve-2025-65573/nvdExploitThird Party Advisory
- github.com/AllskyTeam/allsky/blob/master/html/includes/dashboard_LAN.phpnvdProduct
- github.com/AllskyTeam/allsky/blob/master/html/includes/dashboard_WLAN.phpnvdProduct
- github.com/AllskyTeam/allsky/blob/master/html/includes/functions.phpnvdProduct
News mentions
0No linked articles in our index yet.