CVE-2026-25069

Source
https://cve.org/CVERecord?id=CVE-2026-25069
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25069.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-25069
Published
2026-01-31T23:46:59.669Z
Modified
2026-07-16T03:30:59.473863620Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
SunFounder Pironman Dashboard <= 1.3.13 Path Traversal Arbitrary File Read/Deletion
Details

SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauthenticated remote attacker can supply traversal sequences via the filename parameter to read and delete arbitrary files. Successful exploitation can disclose sensitive information and delete critical system files, resulting in data loss and potential system compromise or denial of service.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25069.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/sunfounder/pm_dashboard

Affected ranges

Type
GIT
Repo
https://github.com/sunfounder/pm_dashboard
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.3.13"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.1.7
1.2.3
1.2.4
1.2.5
1.2.6
1.3.0
1.3.10
1.3.11
1.3.12
1.3.13
1.3.2
1.3.3
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25069.json"