CVE-2025-34073

NONE
CVSS v3
CVSS v2
65.83% EPSS (exploit probability)
CWE-78CWE

Description

An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary operating system commands via the username parameter in a POST request to the /login endpoint. This occurs due to unsafe handling of user-supplied input passed to subprocess.check_output() in core/http.py, allowing injection of shell metacharacters. Exploitation does not require authentication and commands are executed with the privileges of the Maltrail process.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references