Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2025-21433 | A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated attacker can inject arbitrary shell commands through crafted values in the NCSA user creation form fields, leading to command execution with web server privileges. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | 
Tue, 15 Jul 2025 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 15 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 15 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 15 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI interface. An authenticated attacker can inject arbitrary shell commands through crafted values in the NCSA user creation form fields, leading to command execution with web server privileges. | |
| Title | IPFire < 2.19 Core Update 101 proxy.cgi RCE | |
| Weaknesses | CWE-20 CWE-306 CWE-78 | |
| References |  | 
 | 
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-07-15T13:39:22.675Z
Reserved: 2025-04-15T19:15:22.560Z
Link: CVE-2025-34116
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-07-15T13:38:08.992Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-07-15T13:15:32.493
Modified: 2025-07-15T20:07:28.023
Link: CVE-2025-34116
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    Updated: 2025-07-16T21:35:32Z