216.73.217.80

CVE-2025-34121

· Published 16/07/2025 21:15 · Modified 17/07/2025 21:15

Labels: CVE-2025-34121 2025-07-16CVE-2025-34121CWE-306[email protected]

Essential information

Published
16/07/2025 21:15
Modified
17/07/2025 21:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code execution as the web server user. NOTE: The bypass for this vulnerability is tracked as CVE-2015-9263.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
idera / up.time monitoring station cpe:2.3:a:idera:up.time_monitoring_station:7.2:*:*:*:*:*:*:*

References