PT-2025-50582 · Webmin+1 · Webmin+1

Filippo Decortes

·

Published

2025-12-11

·

Updated

2026-04-01

·

CVE-2025-67738

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Webmin versions prior to 2.600
Description The application does not properly handle arguments within the cachemgr.cgi script when the Squid module and its Cache Manager feature are enabled. This issue arises if an unauthorized user gains access to Webmin and possesses specific Cache Manager permissions, specifically the "cms" security option. The problem occurs when arguments are not correctly quoted, potentially leading to unintended consequences.
Recommendations Update to Webmin version 2.600 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2026-05707
CVE-2025-67738

Affected Products

Red Os
Webmin