PT-2025-4373 · Unknown · Pingvin Share

Adam Kornerud

+1

·

Published

2025-01-08

·

Updated

2025-01-08

·

CVE-2025-22137

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pingvin Share versions prior to 1.4.0
Description This issue allows an authenticated or unauthenticated user to overwrite arbitrary files on the server, including sensitive system files, via HTTP POST requests.
Recommendations For versions prior to 1.4.0, update to version 1.4.0 to resolve the issue. As a temporary workaround, consider restricting access to the server or disabling anonymous shares to minimize the risk of exploitation.

Exploit

Fix

Unrestricted File Upload

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22137
GHSA-RJWX-P44F-MCRV

Affected Products

Pingvin Share