A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uploaded, the attacker can trigger the execution of arbitrary commands on the target system, allowing for remote code execution. This could lead to escalation of privileges depending on the privileges of the web server process. The attack does not require physical access and can be conducted remotely, posing a significant risk to the confidentiality and integrity of the system.
History

Thu, 07 Aug 2025 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Twisted
Twisted twisted
Vendors & Products Twisted
Twisted twisted

Tue, 05 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 05 Aug 2025 17:45:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerability by sending a specially crafted HTTP PUT request to upload a malicious file (e.g., a reverse shell script). Once uploaded, the attacker can trigger the execution of arbitrary commands on the target system, allowing for remote code execution. This could lead to escalation of privileges depending on the privileges of the web server process. The attack does not require physical access and can be conducted remotely, posing a significant risk to the confidentiality and integrity of the system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-05T00:00:00.000Z

Updated: 2025-08-05T20:02:00.472Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50688

cve-icon Vulnrichment

Updated: 2025-08-05T20:01:56.274Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-05T18:15:32.083

Modified: 2025-08-05T21:06:25.813

Link: CVE-2025-50688

cve-icon Redhat

No data.