A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Suse
Suse manager
Suse manager Proxy
Suse manager Server
Vendors & Products Suse
Suse manager
Suse manager Proxy
Suse manager Server

Thu, 30 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Oct 2025 10:45:00 +0000

Type Values Removed Values Added
Description A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses.
Title susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversal
Weaknesses CWE-35
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2025-10-31T03:55:25.371Z

Reserved: 2025-07-11T10:53:52.681Z

Link: CVE-2025-53880

cve-icon Vulnrichment

Updated: 2025-10-30T13:38:31.030Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-30T11:15:33.130

Modified: 2025-10-30T15:03:13.440

Link: CVE-2025-53880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-30T14:37:22Z