PT-2025-36400 · Fog · Fog

Casp3R0X0

·

Published

2025-09-06

·

Updated

2025-09-08

·

CVE-2025-58443

CVSS v4.0

9.9

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions FOG versions 1.5.10.1673 and below
Description FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below contain an authentication bypass that allows an unauthenticated attacker to perform a full SQL database dump without credentials.
Recommendations Upgrade to the latest version of either the dev-branch or working-1.6 branch.

Exploit

Fix

RCE

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-58443
GHSA-MVWM-9M2H-87P9

Affected Products

Fog