CVE-2025-53880 Details
Description
A Path Traversal vulnerability in the tftpsync/add and tftpsync/delete scripts allows a remote attacker on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. Although the endpoint is unauthenticated, access is restricted to a list of allowed IP addresses.
A path traversal vulnerability has been identified in the SUSE Manager Proxy tftpsync/add and tftpsync/delete scripts. This vulnerability allows remote attackers on an adjacent network to write or delete files on the filesystem with the privileges of the unprivileged wwwrun user. The issue arises because the scripts fail to properly sanitize user-provided directory and file_name parameters, explicitly allowing absolute paths. As a result, attackers can manipulate file uploads to overwrite critical PXE boot configurations or hijack the provisioning process of new servers.
Users can update to the latest SUSE Manager Proxy or SUSE Manager Server versions, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 30, 2025CISA-ADP
Assessed Oct 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2025-53880 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-35 | Path Traversal: '.../...//' | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SUSE Manager Proxy | All versions |
CPE
Remediation
| |
| SUSE Manager Server | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 30, 2025 | New CVE Received | [email protected] |
Volerion