CVE-2025-25269
published 2025-07-08CVE-2025-25269: An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.
PriorityP345high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.24%
15.2th percentile
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phoenix_contact | charx_sec-3000 | >= 0.0.0 < 1.7.3 | 1.7.3 |
| phoenix_contact | charx_sec-3050 | >= 0.0.0 < 1.7.3 | 1.7.3 |
| phoenix_contact | charx_sec-3100 | >= 0.0.0 < 1.7.3 | 1.7.3 |
| phoenix_contact | charx_sec-3150 | >= 0.0.0 < 1.7.3 | 1.7.3 |
| phoenixcontact | charx_sec-3000_firmware | < 1.7.3 | 1.7.3 |
| phoenixcontact | charx_sec-3050_firmware | < 1.7.3 | 1.7.3 |
| phoenixcontact | charx_sec-3100_firmware | < 1.7.3 | 1.7.3 |
| phoenixcontact | charx_sec-3150_firmware | < 1.7.3 | 1.7.3 |
| struktur | libheif | >= 0 < 1.17.6-1ubuntu4.2 | 1.17.6-1ubuntu4.2 |
| struktur | libheif | >= 0 < 1.20.2-1ubuntu0.1 | 1.20.2-1ubuntu0.1 |
| struktur | libheif | >= 0 < 1.1.0-2ubuntu0.1~esm2 | 1.1.0-2ubuntu0.1~esm2 |
| struktur | libheif | >= 0 < 1.6.1-1ubuntu0.1~esm2 | 1.6.1-1ubuntu0.1~esm2 |
| struktur | libheif | >= 0 < 1.12.0-2ubuntu0.1~esm2 | 1.12.0-2ubuntu0.1~esm2 |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libheif vulnerabilities
osv·2026-01-12·CVSS 7.5
CVE-2024-25269 libheif vulnerabilities
libheif vulnerabilities
It was discovered that libheif did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS
and Ubuntu 24.04 LTS. (CVE-2024-25269)
Aldo Ristori discovered that libheif did not correctly handle certain
memory operations. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2025-68431)
GHSA
GHSA-4435-w7hr-8qwm: An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation
ghsa_unreviewed·2025-07-08
CVE-2025-25269 [HIGH] CWE-78 GHSA-4435-w7hr-8qwm: An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-08
Published