216.73.216.6

CVE-2025-59099

· Published 26/01/2026 10:16 · Modified 26/01/2026 15:03

Labels: CVE-2025-59099 2026-01-26551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2025-59099CWE-35

Essential information

Published
26/01/2026 10:16
Modified
26/01/2026 15:03
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication. Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information and the corresponding PIN codes. Additionally, when trying to access certain files, the web server crashes and becomes unreachable for about 60 seconds. This can be abused to continuously send the request and cause denial of service.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

Affected products (CPE)

ProductCPE
compactwebserver / compactwebserver cpe:2.3:a:compactwebserver:compactwebserver:*:*:*:*:*:*:*:*

References