PT-2025-18727 · Webmin · Webmin
Published
2025-05-01
·
Updated
2025-06-26
·
CVE-2025-2774
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Webmin versions prior to 2.302
Description
A critical vulnerability in Webmin allows authenticated remote attackers to escalate privileges to root-level, risking severe server compromise. The vulnerability is caused by improper CRLF sequence handling, enabling attackers to execute arbitrary commands. The ramifications of this vulnerability are immense, potentially allowing malicious actors to steal data, disrupt services, or install malware on the compromised systems. No known widespread exploitation has occurred yet, but urgency is advised.
Recommendations
For Webmin versions prior to 2.302, update to version 2.302 or later to resolve the issue. As a temporary workaround, consider restricting access to trusted networks and ensuring robust authentication practices to mitigate risks. Additionally, administrators should stay vigilant and keep abreast of security advisories to avoid falling prey to potential attacks.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webmin