CVE-2025-47423
MEDIUM 5.8EPSS 2.0%
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.
- CVSS v3.1
- 5.8 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N - EPSS
- 2.00% chance of exploitation in the next 30 days, 79th percentile
- Nuclei
- high · CWE-24
- Published
- 2025-05-07