peter bassill · operator
$ cve CVE-2025-27920 JSON

CVE-2025-27920 KEV

7.2
HIGH · CVSS 3.1 · EPSS 1.9% (pctl 78)

Patch first

On CISA KEV — known exploited in the wild, due 2025-06-09.

Description

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

Scoring

CVSS7.2 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS1.86% — more likely to be exploited than 78% of all CVEs
WeaknessCWE-24
On CISA KEVyes — remediate by 2025-06-09
Public exploitnone known
Published2025-05-05
Last modified2026-06-17

CISA KEV

NameSrimax Output Messenger Directory Traversal Vulnerability
Added2025-05-19
Due2025-06-09
Vendor / productSrimax / Output Messenger
Ransomware usenone reported

Affected (1)

VendorProduct
srimaxoutput messenger

References

→ the Explorer  ·  watch your stack  ·  NVD