PT-2025-18727 · Webmin · Webmin

Published

2025-05-01

·

Updated

2025-06-26

·

CVE-2025-2774

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Webmin versions prior to 2.302
Description A critical vulnerability in Webmin allows authenticated remote attackers to escalate privileges to root-level, risking severe server compromise. The vulnerability is caused by improper CRLF sequence handling, enabling attackers to execute arbitrary commands. The ramifications of this vulnerability are immense, potentially allowing malicious actors to steal data, disrupt services, or install malware on the compromised systems. No known widespread exploitation has occurred yet, but urgency is advised.
Recommendations For Webmin versions prior to 2.302, update to version 2.302 or later to resolve the issue. As a temporary workaround, consider restricting access to trusted networks and ensuring robust authentication practices to mitigate risks. Additionally, administrators should stay vigilant and keep abreast of security advisories to avoid falling prey to potential attacks.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-05192
CVE-2025-2774
ZDI-25-282

Affected Products

Webmin