← Back to browse · API

CVE-2025-53120

Severity
CRITICAL
CVSS
9.4
EPSS
0.09239
Risk score
40.83
CISA KEV
No
PoC
No
Published
2025-08-25
Modified
2025-08-25
First seen
2026-08-07
Aliases
EUVD-2025-25723, GHSA-CMV4-9RJR-99H2
Products
Securden:Unified PAM 9.0.* ≤11.3.1
Sources
euvd EUVD-2025-25723

Description

A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on the Unified PAM server.

References