CVE-2025-34073
NONE—CVSS v3
—CVSS v2
65.83%
EPSS (exploit probability)
CWE-78CWE
Description
An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary operating system commands via the username parameter in a POST request to the /login endpoint. This occurs due to unsafe handling of user-supplied input passed to subprocess.check_output() in core/http.py, allowing injection of shell metacharacters. Exploitation does not require authentication and commands are executed with the privileges of the Maltrail process.
Affected routers (0)
No routers currently mapped to this CVE in our database.