CVE-2025-63261
published 2026-03-20CVE-2025-63261: AWStats 8.0 is vulnerable to Command Injection via the open function
PriorityP352high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
1.05%
60.4th percentile
AWStats 8.0 is vulnerable to Command Injection via the open function
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| awstats | awstats | — | — |
| awstats | awstats | >= 0 < 7.8-2+deb11u2 | 7.8-2+deb11u2 |
| awstats | awstats | >= 0 < 8.0-5 | 8.0-5 |
| debian | awstats | < awstats 7.8-2+deb11u2 (bullseye) | awstats 7.8-2+deb11u2 (bullseye) |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-63261: awstats - AWStats 8.0 is vulnerable to Command Injection via the open function
vendor_debian·2025·CVSS 7.8
CVE-2025-63261 [HIGH] CVE-2025-63261: awstats - AWStats 8.0 is vulnerable to Command Injection via the open function
AWStats 8.0 is vulnerable to Command Injection via the open function
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.8-2+deb11u2)
forky: resolved (fixed in 8.0-5)
sid: resolved (fixed in 8.0-5)
trixie: open
GHSA
GHSA-f93m-5ch9-5cqf: AWStats 8
ghsa_unreviewed·2026-03-20
CVE-2025-63261 [HIGH] CWE-78 GHSA-f93m-5ch9-5cqf: AWStats 8
AWStats 8.0 is vulnerable to Command Injection via the open function
OSV
CVE-2025-63261: AWStats 8
osv·2026-03-20·CVSS 7.8
CVE-2025-63261 [HIGH] CVE-2025-63261: AWStats 8
AWStats 8.0 is vulnerable to Command Injection via the open function
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [fedora-42]
bugzilla·2026-03-23·CVSS 7.8
CVE-2025-63261 [HIGH] CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [fedora-42]
CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-29b65f46e8 (awstats-8.0-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-29b65f46e8
Bugzilla
CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [fedora-43]
bugzilla·2026-03-23·CVSS 7.8
CVE-2025-63261 [HIGH] CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [fedora-43]
CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-fad30cb6e2 (awstats-8.0-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-fad30cb6e2
Bugzilla
CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [epel-all]
bugzilla·2026-03-23·CVSS 7.8
CVE-2025-63261 [HIGH] CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [epel-all]
CVE-2025-63261 awstats: AWStats: Arbitrary code execution via command injection vulnerability [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
I understand that AWStats is no longer being actively maintained and is slated for removal from future Fedora packages. However, given the impact of the recent vulnerability (CVE-2025-63261), could you please consider addressing this issue?
It appears that a patch has been proposed in the following issue:
https://github.com/eldy/AWStats/issues/287
Could you please review this and let me know if it's possible to apply the fix? Thank you for your time
Bugzilla
CVE-2025-63261 AWStats: AWStats: Arbitrary code execution via command injection vulnerability
bugzilla·2026-03-20·CVSS 7.8
CVE-2025-63261 [HIGH] CVE-2025-63261 AWStats: AWStats: Arbitrary code execution via command injection vulnerability
CVE-2025-63261 AWStats: AWStats: Arbitrary code execution via command injection vulnerability
AWStats 8.0 is vulnerable to Command Injection via the open function
Discussion:
Per the vulnerability report, "To perform this exploit, an attacker must find a way to create or modify the “awstats.confˮ file with malicious content" (specifically, modifying DNSLastUpdateCacheFile to contain a malicious value and potentially changing the values of other, enabling, options)
Unless I'm misunderstanding the vulnerability report, this is only really an issue if a user has write-access to awstats.conf, and that configuration file is subsequently used by a *different* user (for example, "root", or "apache") running awstats, thereby enabling code execution by that (second) user. Or if a user has the a
Wiz
CVE-2025-63261 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2025-63261 [HIGH] CVE-2025-63261 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63261 :
Linux Debian vulnerability analysis and mitigation
AWStats 8.0 is vulnerable to Command Injection via the open function
Source : NVD
## 7.8
Score
Published March 20, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
Linux Debian
Echo
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
awstats
Sources
NVD
Debian 11 Severity HIGH Has Fix Added at: Mar 21, 2026
Debian 12, 13, 14 Severity LOW No Fix Added at: Mar 21, 2026
Echo Severity HIGH No Fix Added at: Mar 21, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, n
2026-03-20
Published