PT-2025-34689 · Docker+1 · Docker+1

Privt00

·

Published

2025-08-25

·

Updated

2025-08-26

·

CVE-2025-57802

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Airlink versions prior to 1.0.1
Description: Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. An attacker with access to the affected container can create symbolic links inside the mounted directory (/app/data). These symlinks can point to sensitive locations on the host filesystem due to the container bind-mounting an arbitrary host path. When the application or other processes follow these symlinks, the attacker can gain unauthorized read access to host files outside the container.
Recommendations: Update to version 1.0.1 or later.

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-57802
GHSA-HRFV-WM8P-MG8M

Affected Products

Airlink
Docker