216.73.217.22

CVE-2025-57439

· Published 22/09/2025 18:15 · Modified 22/09/2025 21:22

Labels: CVE-2025-57439 2025-09-22CVE-2025-57439CWE-94[email protected]

Essential information

Published
22/09/2025 18:15
Modified
22/09/2025 21:22
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacker can inject arbitrary Lua code into the configuration, which is then executed on the server. This allows full system compromise, including reverse shell execution or arbitrary command execution.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
creacast / creabox manager cpe:2.3:a:creacast:creabox_manager:4.4.4:*:*:*:*:*:*:*

References