PT-2025-31881 · Ratpanel · Ratpanel

Ltltlxey

·

Published

2025-08-04

·

Updated

2025-08-19

·

CVE-2025-53534

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RatPanel versions 2.3.19 through 2.5.5
Description RatPanel is susceptible to remote code execution (RCE) and unauthorized access. An attacker who obtains the backend login path of RatPanel can execute system commands or take over hosts managed by the panel without logging in. This is due to the CleanPath middleware not processing r.URL.Path, leading to path misinterpretation and authentication bypass. Specifically, the vulnerability affects the must login middleware, allowing access to dangerous interfaces such as /api/ws/exec and /api/ws/ssh. Exploitation requires activating a session, but does not require completing the full authentication process.
Recommendations RatPanel versions 2.3.19 through 2.5.5 are affected and should be updated to version 2.5.6 or later.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-53534
GHSA-FM3M-JRGM-5PPG
GO-2025-3844
OPENSUSE-SU-2025:15434-1
SUSE-SU-2025:02912-1

Affected Products

Ratpanel