PT-2025-4386 · Atheros · Atheos

Wangyihang

·

Published

2025-01-10

·

Updated

2025-05-15

·

CVE-2025-22152

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Atheos versions prior to v600
Description Atheos is a self-hosted browser-based cloud IDE. The issue is related to the lack of proper validation of the $path and $target parameters across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. This can be exploited through various attack vectors present in multiple PHP files.
Recommendations For versions prior to v600, update to v600 to fix the issue. As a temporary workaround, consider restricting access to the vulnerable parameters $path and $target to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Unrestricted File Upload

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-01220
CVE-2025-22152
GHSA-RGJM-6P59-537V

Affected Products

Atheos