CVE-2025-52361

Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authenticated low-privilege user to execute arbitrary commands with root privilege via editing this script which is executed with root-privileges on any interaction and on every system boot.
Configurations

No configuration.

History

04 Aug 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-276

04 Aug 2025, 15:06

Type Values Removed Values Added
Summary
  • (es) Los permisos inseguros en el script /etc/init.d/lighttpd en el firmware v0.0.16 Build 2023-03-13 de AK-Nord USB-Server-LXL permiten que un usuario con privilegios bajos autenticado localmente ejecute comandos arbitrarios con privilegios de root mediante la edición de este script que se ejecuta con privilegios de root en cualquier interacción y en cada arranque del sistema.

01 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-01 16:15

Updated : 2025-08-04 17:15


NVD link : CVE-2025-52361

Mitre link : CVE-2025-52361

CVE.ORG link : CVE-2025-52361


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions